Skip to content
This repository has been archived by the owner on Dec 28, 2023. It is now read-only.

Usage of exact version of minimist #214

Open
z0r0132 opened this issue Apr 6, 2020 · 4 comments
Open

Usage of exact version of minimist #214

z0r0132 opened this issue Apr 6, 2020 · 4 comments

Comments

@z0r0132
Copy link

z0r0132 commented Apr 6, 2020

The version used for minimist is 1.2.0.
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "proto" payload.

I cannot change in my project, even if I install latest of minimist, karma-mocha still install 1.2.0 and uses it, can you please check that and update, it is critical in my project.
Thanks

@franktopel
Copy link
Contributor

franktopel commented Apr 6, 2020

To whoever is able to maintain this project:

Additional information

Please see https://npmjs.com/advisories/1179 as of what exactly is the problem here.

karma itself has this problem, and they have addressed it in this commit. The only thing currently preventing @johnjbarton from releasing a new version of karma containing that fix seems to be Travis-related problems which aforementioned repo owner announced to address today.

Please upgrade your dependency asap to a version >= 1.2.3.

@franktopel
Copy link
Contributor

@johnjbarton The latest release of this package dates back to 2016. Who can issue a new release with this fix in it?

@johnjbarton
Copy link
Contributor

I will work on semantic-release...after I get it to work on the karma-runner/karma project.

@franktopel
Copy link
Contributor

I think this can be closed as of release 2.0.0.

# for free to subscribe to this conversation on GitHub. Already have an account? #.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants