-
Notifications
You must be signed in to change notification settings - Fork 97
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
update minimist to handle security vulnerability #114
Conversation
@dominictarr approved and ready to merge |
Ah yeah, npm could be more deterministic. I switched to yarn. |
For anyone else reading this: it looks like some of the difficulties identifying the source of the For example
I think that means that the dependency that does the bundling will have to be updated in order for upstream projects to see a fix, since the downloaded copy of an existing, unfixed package containing bundles will continue to provide the dependencies regardless of semver rules. |
Resolves issue 113