Navigation Menu

Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability [ Prototype Pollution] #241

Closed
AsathalMannan opened this issue May 2, 2020 · 4 comments · Fixed by #256
Closed

Vulnerability [ Prototype Pollution] #241

AsathalMannan opened this issue May 2, 2020 · 4 comments · Fixed by #256
Labels

Comments

@AsathalMannan
Copy link

AsathalMannan commented May 2, 2020

Package: yargs-parser
Patched-in: >=13.1.2 <14.0.0 || >=15.0.1 <16.0.0 || >=18.1.2
Dependency of: gatsby-plugin-robots-txt
Path: gatsby-plugin-robots-txt > generate-robotstxt > meow > yargs-parser
More-info: (https://npmjs.com/advisories/1500)

@mvantol1
Copy link

mvantol1 commented May 18, 2020

The underlying dependency is already updated in #246, however no new release was made yet. Is it possible to make a new release so that the issue can be resolved?

@mdreizin
Copy link
Owner

@AsathalMannan Thanks for the report. I am working on a new release. It will be available within 1 hours. /cc @mvantol1.

@mdreizin
Copy link
Owner

@AsathalMannan @mvantol1 Please upgrade to 1.5.1.

@github-actions
Copy link

🎉 This issue has been resolved in version 1.5.1 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
3 participants