-
Notifications
You must be signed in to change notification settings - Fork 10
Open
Description
Hello,
Using dicer dependency may result in crashes, according to npm when running npm install
with batchelor 2.0.2 in package.json:
dicer *
Severity: high
Crash in HeaderParser in dicer - https://github.com/advisories/GHSA-wm7h-9275-46v2
No fix available
node_modules/dicer
batchelor *
Depends on vulnerable versions of dicer
node_modules/batchelor
Please check the corresponding issue opened in dicer repo. A PR on dicer is opened since more than one year, a quick fix should not be expected on that side...
Metadata
Metadata
Assignees
Labels
No labels