-
Notifications
You must be signed in to change notification settings - Fork 291
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Command Injection due to old node-modules #421
Comments
Just one more reason to switch to jest. I've committed my package lock file and now my repo is marked as vulnerable. |
1 year has passed and this is still not fixed. 😢 |
Just need to upgrade |
I see this has been addressed, caused breaking changes, and was reverted: #433 |
So please fix this! |
I forked and fixed this. Feel free to use it in the meanwhile: Just remember that, like discussed, it will not support
|
Any chance you can update the jasmine-growl-reporter package to version 1.0.1? There is a security vulnerability in the current version (0.0.3)
Once you get this fixed, other library's that depend on your library can be updated as well.
Thanks
The text was updated successfully, but these errors were encountered: