blk-design-system icon indicating copy to clipboard operation
blk-design-system copied to clipboard

Vulnerabilities of packages

Open adefirmanf opened this issue 4 years ago • 2 comments

Hello team, we find some several issues regarding the vulnerabilities on packages when running npm install

found 8 vulnerabilities (1 low, 6 high, 1 critical)

I concern about the critical one. Could someone update the package.json / package.lock.json ?

adefirmanf avatar Apr 14 '20 15:04 adefirmanf

Anyway, the .gitignore should be included in the repository. So, node_modules doesn't push to the repository

adefirmanf avatar Apr 14 '20 15:04 adefirmanf

Hi @adefirmanf,

Thank you for working with our products.

We will take a closer look to the packages and update them on our next release. Please run npm audit fix and it should work fine.

I hope it helps.

All the best, Rares

rarestoma avatar Apr 15 '20 07:04 rarestoma