Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Prototype pollution in dot-prop@4.2.0 which is used in update-notifier@2.5.0 #8082

Closed
sumit-tw opened this issue Aug 14, 2020 · 2 comments
Closed

Comments

@sumit-tw
Copy link

sumit-tw commented Aug 14, 2020

A security check fails for Serverless in versions 1.71.1 to 1.78.1

serverless.yml
# ⚠️⚠️ REPLACE THIS COMMENT WITH FULL serverless.yml CONTENT
⚠️⚠️ REPLACE WITH FULL COMMAND NAME output
⚠️⚠️ REPLACE WITH FULL COMMAND OUTPUT

Installed version

⚠️⚠️ REPLACE WITH `serverless --version` OUTPUT
@instantlinux
Copy link

Dup? Check #7486

@medikoo
Copy link
Contributor

medikoo commented Aug 18, 2020

Duplicate of #7486

@medikoo medikoo marked this as a duplicate of #7486 Aug 18, 2020
@medikoo medikoo closed this as completed Aug 18, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants