-
Notifications
You must be signed in to change notification settings - Fork 94
Closed
Description
The c8 dependency istanbul-lib-report is causing a moderate security vulnerability finding. I've reported this directly on their repo: istanbuljs/istanbuljs#725 However, that repo was last updated in 2022, so I wanted to let you know too.
make-dir 2.0.0 - 3.1.0
Depends on vulnerable versions of semver
node_modules/make-dir
istanbul-lib-report >=2.0.5
Depends on vulnerable versions of make-dir
node_modules/istanbul-lib-report
c8 >=5.0.3
Depends on vulnerable versions of istanbul-lib-report
Depends on vulnerable versions of istanbul-reports
node_modules/c8
Root security finding: GHSA-c2qf-rxjj-qqgw
Please consider using an alternative library if they don't update their dependency. Thanks very much.
hildjj, ericcornelissen, pieterocp, leifnamb, GaelGirodon and 4 more
Metadata
Metadata
Assignees
Labels
No labels