graphqurl icon indicating copy to clipboard operation
graphqurl copied to clipboard

refresh the lockfile to automatically remove the vulnerability introduced by tree-kit

Open paimon0715 opened this issue 2 years ago • 0 comments

Hi, @wawhal, I have reported a vulnerability issue in package terminal-kit.

As far as I am aware, vulnerability(high severity) SNYK-JS-TREEKIT-1077068 detected in package tree-kit<0.7.0 is directly referenced by  [email protected], on which your package [email protected] directly depends. As such, this vulnerability can also affect [email protected] via the following path: [email protected][email protected][email protected](vulnerable version)

Since terminal-kit has released a new patched version [email protected] to resolve this issue ([email protected][email protected](fix version)), then this vulnerability patch can be automatically propagated into your project only if you update your lockfile. The following is your new dependency path : [email protected][email protected][email protected](vulnerability fix version).

dependency path

A warm tip. Best regards, ^_^

paimon0715 avatar Aug 20 '21 08:08 paimon0715