Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

semver@6.3.0 Vulnerability within nyc@15.1.0 #1522

Open
rlerma opened this issue Jun 28, 2023 · 5 comments
Open

semver@6.3.0 Vulnerability within nyc@15.1.0 #1522

rlerma opened this issue Jun 28, 2023 · 5 comments

Comments

@rlerma
Copy link

rlerma commented Jun 28, 2023

Is this repo still being maintained?

nyc has the following dependency tree based on semver

nyc@15.1.0
├─┬ istanbul-lib-instrument@4.0.3
│ ├─┬ @babel/core@7.19.0
│ │ ├─┬ @babel/helper-compilation-targets@7.19.0
│ │ │ └── semver@6.3.0
│ │ └── semver@6.3.0
│ └── semver@6.3.0
└─┬ make-dir@3.1.0
└── semver@6.3.0

semver@<7.5.2 has a vulnerability
GHSA-c2qf-rxjj-qqgw

@rcmedeiros
Copy link

No response? 👀

@AxxlFoley
Copy link

I also need a fix .. any update ?

@TheJHay
Copy link

TheJHay commented Jul 4, 2023

@coreyfarrell are you able to comment if this repo is still maintained?

@jaws97
Copy link

jaws97 commented Jan 3, 2024

Did anyone find any alternative?

@AxxlFoley
Copy link

@jaws97 After realizing that nyc is not really maintained any longer, our project switched to C8
https://github.com/bcoe/c8

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants