Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update version yargs #105

Open
wants to merge 1 commit into
base: master
Choose a base branch
from
Open

update version yargs #105

wants to merge 1 commit into from

Conversation

Fredbnm
Copy link

@Fredbnm Fredbnm commented Mar 10, 2021

it is necessary to update the version of yargs even so that the version of y18n is also updated, thus ruling out possible vulnerabilities.
yargs
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7608
y18n
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7774

@KrishnamoorthySundar
Copy link

Veracode reports yargs-parser and mem as vulnerabilities. Update to 13.1.0 and 4.0.0 respectively is the minimum expectation.
Please do the needful.

@arun-mano
Copy link

Hi @Fredbnm @ocombe , Will there be a new version with the Yargs updated to recent version , so that the CVE vulnerability reported can be address for yargs-parser ?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants