live-server icon indicating copy to clipboard operation
live-server copied to clipboard

"live-server": 1.2.1 references to "chokidar": "^2.0.4" which contains "glob-parent": "^3.1.0"

Open VladimirTrunov opened this issue 2 years ago • 0 comments

Hello everyone,

For "glob-parent" of version "^3.1.0" there is a vulnerability generated: CVE-2020-28469

This vulnerability will be fixed for "live-server" if the related "chokidar" will be updated to at least "^3.0.0"

Could anybody please take a look?

Thanks, -Vladimir

VladimirTrunov avatar Jan 19 '22 03:01 VladimirTrunov