Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Pin colors package to 1.4.0 due to Security Vuln #2008

Merged
merged 1 commit into from
Jan 9, 2022

Conversation

MannyPamintuanWorkAccount
Copy link
Contributor

A Security Vuln was identified in the Colors package for >1.4.0, offending packages being 1.4.1, 1.4.44-liberty

This PR pins the color package to 1.4.0 as advised on the snyk page

A Security Vuln was identified in the Colors package for >1.4.0, offending packages being `1.4.1`, `1.4.44-liberty`

This PR pins the color package to `1.4.0`
@DABH
Copy link
Contributor

DABH commented Jan 9, 2022

Shoot, I thought we had pinned this already. Thank you.

@DABH DABH merged commit 05bda20 into winstonjs:master Jan 9, 2022
@MannyPamintuanWorkAccount
Copy link
Contributor Author

Shoot, I thought we had pinned this already. Thank you.

You're most welcome David (@DABH)! I appreciate the speed of review and approval!

@wbt wbt mentioned this pull request Jan 10, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants