Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

When an advisory lacks vulnerable_versions, use * #4

Closed
wants to merge 2 commits into from

Conversation

isaacs
Copy link
Contributor

@isaacs isaacs commented Feb 13, 2021

Re: npm/cli#1875

References

@isaacs
Copy link
Contributor Author

isaacs commented Feb 13, 2021

Second commit defaults severity to 'high', which seems like a similarly wise precaution.

@isaacs isaacs force-pushed the isaacs/audit-default-vulnerable-versions-to-all branch from 3df1d29 to a6717bf Compare February 13, 2021 00:44
isaacs added a commit to npm/arborist that referenced this pull request Feb 13, 2021
Copy link
Contributor

@nlf nlf left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this makes sense seeing as we have no control over the advisories we get from third parties, and it's a lot easier for us to work around it than it is to make them fix their data

@isaacs isaacs closed this in a2dcf13 Feb 18, 2021
isaacs added a commit to npm/arborist that referenced this pull request Feb 18, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants