Skip to content

Bump json5 version in package-lock.json #1062

@chaoscommencer

Description

@chaoscommencer

Bump json5 versions from 1.0.1 to 1.0.2 and from 2.* to 2.2.2 to address
"Prototype Pollution in JSON5 via Parse Method"
flagged by dependabot.

It may be advisable to enable dependabot alerts on your repository as well for similar future notifications.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions