Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump yargs-parser to 18.1.2 or higher #1794

Closed
theS1LV3R opened this issue Jul 11, 2020 · 5 comments
Closed

Bump yargs-parser to 18.1.2 or higher #1794

theS1LV3R opened this issue Jul 11, 2020 · 5 comments
Labels
馃殌 Feature Request new suggested feature

Comments

@theS1LV3R
Copy link

theS1LV3R commented Jul 11, 2020

馃殌 Feature Proposal

Change yargs-parser dependency in package.json from 18.x to >18.1.1.

Motivation

yargs-parser v18.1.1 and lower has a Prototype Pollution vulnerability (see here and here)

Example

N/A

@theS1LV3R theS1LV3R added the 馃殌 Feature Request new suggested feature label Jul 11, 2020
@theS1LV3R theS1LV3R changed the title Bump yargs-parser to 18.1.2 or higher Bump yargs-parser to 18.1.2 or higher Jul 11, 2020
@ahnpnl
Copy link
Collaborator

ahnpnl commented Jul 11, 2020

Hi, 18.x means it will automatically pick up the latest version of 18. If you simply update your lock file to save 18.1.2, it will solve the issue.

@theS1LV3R
Copy link
Author

I've updated my lockfile multiple times already. I am using the vue ui's vulnerability check. It gives me:
image
I've updated @vue/cli-plugin-unit-jest to the newest version available (4.4.6).

@theS1LV3R
Copy link
Author

Actually, i just realised i should be bugging the vue team about this instead. Get them to use a newer version of ts-jest. Thanks anyways

@ahnpnl
Copy link
Collaborator

ahnpnl commented Jul 11, 2020

FYI vuejs/vue-jest#246 (comment)

@theS1LV3R
Copy link
Author

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
馃殌 Feature Request new suggested feature
Projects
None yet
Development

No branches or pull requests

2 participants