Skip to content
This repository has been archived by the owner on May 6, 2019. It is now read-only.

Currently using vulnerable version of hapijs/hoek #1

Open
rooby opened this issue May 10, 2018 · 0 comments
Open

Currently using vulnerable version of hapijs/hoek #1

rooby opened this issue May 10, 2018 · 0 comments

Comments

@rooby
Copy link
Contributor

rooby commented May 10, 2018

The hapijs/hoek package has a security release and we should use 5.0.3+ or 4.2.1+.

https://github.com/hapijs/hoek
Following the dependency tree up we arrive at the node-sass package, which won't commit the change in their current version as it will be a breaking change.

They are making the switch in v5. When that is released we should update.
See sass/node-sass#2111 & sass/node-sass#2355

Since this is just used for sass compilation, it only potentially affects our development environments, but we should update as soon as we can.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant