Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: upgrade y18n to 5.0.5 to address prototype pollution issue #1795

Merged
merged 2 commits into from Nov 15, 2020

Conversation

DarthHater
Copy link
Contributor

Hi there!

This PR is short and sweet, just updates the package.json to bring in the updates to y18n that address prototype pollution (which I believe is addressed in 5.0.5)

Related:

Let me know if you need anything from me!

Cheers!

@bcoe
Copy link
Member

bcoe commented Nov 15, 2020

@DarthHater I don't usually land patch updates like this, as they'll be covered by the SemVer ^ version range. Thanks for taking the time to submit the PR, however.

@bcoe bcoe changed the title Upgrade y18n to 5.0.5 to address prototype pollution issue chore: upgrade y18n to 5.0.5 to address prototype pollution issue Nov 15, 2020
@bcoe bcoe merged commit ae001f3 into yargs:master Nov 15, 2020
@DarthHater
Copy link
Contributor Author

@bcoe thanks! Never hurts to bump it even if the semver handles it (in case some other dependency is locked to an older version, npm would in theory select a version to satisfy (project a has exact match to 5.0.2, your semver is satisfied)).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants