Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

update the lockfile to automatically remove the high severity vulnerability introduced in @haul-bundler/core #765

Open
paimon0715 opened this issue Aug 20, 2021 · 0 comments

Comments

@paimon0715
Copy link

paimon0715 commented Aug 20, 2021

Hi, @zamotany, I have reported a vulnerability issue in package terminal-kit.

As far as I am aware, vulnerability(high severity) SNYK-JS-TREEKIT-1077068 detected in package tree-kit(<0.7.0) is directly referenced by  terminal-kit@1.49.3, on which your package @haul-bundler/core@0.23.0 directly depends. As such, this vulnerability can also affect @haul-bundler/core@0.23.0 via the following path:
@haul-bundler/core@0.23.0 ➔ terminal-kit@1.49.3 ➔ tree-kit@0.6.2(vulnerable version)

Since terminal-kit has released a new patched version terminal-kit@1.49.4 to resolve this issue (terminal-kit@1.49.4 ➔ tree-kit@0.7.0(fix version)), then this vulnerability patch can be automatically propagated into your project only if you update your lockfile. The following is your new dependency path :
@haul-bundler/core@0.23.0 ➔ terminal-kit@1.49.4 ➔ tree-kit@0.7.0(vulnerability fix version).

dependency path

A warm tip.^_^
Best regards,

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant