-
Notifications
You must be signed in to change notification settings - Fork 3.4k
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Update make-dir
to resolve vulnerable dependency
#3806
Comments
It appears an outdated version of semver is also referenced as a dev dependency here: less.js/packages/less/package.json Line 100 in 4d3189c
|
@iChenLei, is there any update on this? If not, would a pull request be welcome? |
it was fixed on |
That will only fix it if you use This means it would be best if Dunno if this repo is still maintained but I'd be open to creating a pull request. |
@jorenbroekema PR welcome |
the less.js dependency
make-dir
is not up-to-date and causes security warning due to its outdated dependency.see GHSA-c2qf-rxjj-qqgw
I would suggest updating to a current
make-dir
version here.A quick search showed that it is only used here, so from my point of view an update should bring little problems.
less.js/packages/less/bin/lessc
Lines 163 to 172 in 7491578
The text was updated successfully, but these errors were encountered: