jasmine-node icon indicating copy to clipboard operation
jasmine-node copied to clipboard

Updated jasmine-growl-reporter to fix critical vulnerability in Jasmine2.0

Open beckyconning opened this issue 6 years ago • 2 comments

beckyconning avatar Feb 01 '19 15:02 beckyconning

Thanks @beckyconning. Considering that the Jasmine2.0 branch was already abandoned (see [1]), this proposal will probably not be integrated.

[1] https://github.com/mhevery/jasmine-node#jasmine

brodycj avatar May 21 '19 20:05 brodycj

In an ideal world everyone would update to the latest software regardless of breaking changes. However time and labour aren't free.

This seems to be a case where changing two characters will improve the security of legacy software.

Why prevent such a change?

beckyconning avatar May 13 '20 09:05 beckyconning