Skip to content
This repository has been archived by the owner on Mar 25, 2021. It is now read-only.

Vulnerability in minimist, need to upgrade to latest version #4921

Closed
jlcard opened this issue Apr 2, 2020 · 5 comments
Closed

Vulnerability in minimist, need to upgrade to latest version #4921

jlcard opened this issue Apr 2, 2020 · 5 comments

Comments

@jlcard
Copy link

jlcard commented Apr 2, 2020

tslint.5.17.0 (https://www.nuget.org/packages/tslint/5.17.0) includes minimist module version 0.0.8 which has a vulnerability.
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7598
Can you please release a new version of tslint with upgraded minimist to latest version (1.2.5) (https://www.npmjs.com/package/minimist)

@JoshuaKGoldberg
Copy link
Contributor

Oh, that's right, we never did resolve #1017. I can do this soon for the 6.X line.

@JoshuaKGoldberg JoshuaKGoldberg self-assigned this Apr 2, 2020
@jlcard
Copy link
Author

jlcard commented Apr 2, 2020

Once fixed, can you please publish to https://www.nuget.org/ too?

@JoshuaKGoldberg
Copy link
Contributor

To be clear @jlcard this was actually fixed in #4917. You're just looking at an old version of TSLint. 6.1.1 is the current.

This issue is exclusively for publishing a new version to nuget.org.

@JoshuaKGoldberg
Copy link
Contributor

All right, 6.1.1 is published on the NuGet Gallery: https://www.nuget.org/packages/tslint/

It's also correctly noted there as deprecated. We should all switch to typescript-eslint per #4534. Cheers!

@JoshuaKGoldberg
Copy link
Contributor

🤖 Beep boop! 👉 TSLint is deprecated 👈 and you should switch to typescript-eslint! 🤖

🔒 This issue is being locked to prevent further unnecessary discussions. Thank you! 👋

@palantir palantir locked and limited conversation to collaborators Sep 15, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

2 participants