Skip to content

Update fsevents to the most recent minor version to remove minimist vulnerability#993

Closed
mjziolko wants to merge 1 commit intopaulmillr:2.xfrom
mjziolko:fsevents-vuln
Closed

Update fsevents to the most recent minor version to remove minimist vulnerability#993
mjziolko wants to merge 1 commit intopaulmillr:2.xfrom
mjziolko:fsevents-vuln

Conversation

@mjziolko
Copy link
Copy Markdown

@mjziolko mjziolko changed the base branch from master to 2.x March 18, 2020 07:11
@mjziolko
Copy link
Copy Markdown
Author

mjziolko commented Mar 18, 2020

Might need to create a new target branch to get a new minor version out with this package update. webpack/watchpack relies on this semver and currently has a prototype pollution vulnerability in minimist: https://npmjs.com/advisories/1179

@paulmillr
Copy link
Copy Markdown
Owner

^1.2.2 includes 1.2.11. What's the deal here?

@paulmillr
Copy link
Copy Markdown
Owner

You also have invalid commit. Current chokidar 2.x branch uses fsevents ^1.2.7.

@mjziolko
Copy link
Copy Markdown
Author

Yup, sorry made this PR in error. There's some issues with the semver being pinned/the mkdirp package changing hands and I've been staring at version numbers for an hour. I'll close this!

@mjziolko mjziolko closed this Mar 18, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants