Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security warning tiny-lr@0.2.1: Update tiny-lr #553

Closed
lacymorrow opened this issue Feb 27, 2018 · 2 comments
Closed

Security warning tiny-lr@0.2.1: Update tiny-lr #553

lacymorrow opened this issue Feb 27, 2018 · 2 comments

Comments

@lacymorrow
Copy link

Prototype Override Protection Bypass SEVERITY: HIGH
Discovered in a nested dependency: grunt-contrib-watch@1.0.0tiny-lr@0.2.1qs@5.1.0
https://snyk.io/vuln/npm:qs:20170213?utm_source=bithound

Prototype Override Protection Bypass SEVERITY: HIGH
Discovered in a nested dependency: grunt-contrib-watch@1.0.0tiny-lr@0.2.1body-parser@1.14.2qs@5.2.0
https://snyk.io/vuln/npm:qs:20170213?utm_source=bithound

Regular Expression Denial of Service (ReDoS) SEVERITY: LOW
Discovered in a nested dependency: grunt-contrib-watch@1.0.0tiny-lr@0.2.1debug@2.2.0ms@0.7.1
https://snyk.io/vuln/npm:ms:20170412?utm_source=bithound

Security warnings are present in many packages used by tiny-lr, please update to a secure version.

@schlenks
Copy link

schlenks commented May 9, 2018

@shama would it be possible for you to do an update to resolve this security issue? It's rated high severity.

@shama
Copy link
Member

shama commented May 13, 2018

Fixed with #543 thanks!

@shama shama closed this as completed May 13, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants