Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump packages to prevent vulnerabilities and remove unused gulp and package-lock.json #964

Merged
merged 3 commits into from Jul 27, 2018

Conversation

YuCJ
Copy link
Collaborator

@YuCJ YuCJ commented Jul 27, 2018

hoek under 4.2.1 is still reported vulnerable but it is be used by the dependencies of node-sass and chokidar (depended by babel-cli, nodemon, webpack, webpack-dev-server, pm2). Since these libraries are all dev dependencies running on server and not exposed to enduser, its not so critical with the problem that the prototype of Object can be mutated.

Ref:
https://nvd.nist.gov/vuln/detail/CVE-2018-3728
sass/node-sass#2355 (comment)
fsevents/fsevents#201

@nickhsine
Copy link
Collaborator

LGTM 👍

@YuCJ YuCJ merged commit dbef265 into twreporter:master Jul 27, 2018
@YuCJ YuCJ deleted the vulner branch February 18, 2019 09:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants