global-prefix icon indicating copy to clipboard operation
global-prefix copied to clipboard

ini 1.3.5 dependency has prototype pollution

Open adityapant1286 opened this issue 3 years ago • 2 comments

There is low-level vulnerability for ini 1.3.5 dependency. Unfortunately, this version has seen the end of life and the current version is 2.0.0. Is it possible to update the dependency to the latest version?

adityapant1286 avatar Jan 10 '21 23:01 adityapant1286

This looks like a duplicate of #26.

stieben avatar Apr 07 '21 17:04 stieben

The caret (^) in the semver range actually means you will already get that bugfix patch! You just need to remove your lockfile and reinstall your dependencies.

phated avatar Apr 07 '21 18:04 phated