Skip to content

Commit

Permalink
Bump minimist from 1.2.0 to 1.2.5
Browse files Browse the repository at this point in the history
minimist@1.2.2 and earlier had "a prototype pollution bug that could
cause privilege escalation in some circumstances when handling untrusted
user input." [Source: https://github.com/substack/minimist#security]

Unfortunately, mocha@7.x also has a dependency on a vulnerable minimist
version through the mkdirp package; but at this point it seems likely
that this will only get addressed in mocha@8.0:
mochajs/mocha#4199.

This update partially addresses the security alert raised by GitHub in
https://github.com/aerospike/aerospike-client-nodejs/network/alert/package-lock.json/minimist/open
  • Loading branch information
jhecking committed Mar 16, 2020
1 parent c03ddf0 commit 43f0b93
Showing 1 changed file with 14 additions and 12 deletions.
26 changes: 14 additions & 12 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

0 comments on commit 43f0b93

Please sign in to comment.