Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security vulnerabilities in dependencies reported by npm audit #34

Closed
ghost opened this issue Jun 19, 2018 · 3 comments
Closed

Security vulnerabilities in dependencies reported by npm audit #34

ghost opened this issue Jun 19, 2018 · 3 comments

Comments

@ghost
Copy link

ghost commented Jun 19, 2018

npm audit is reporting security vulnerabilities in some of karma-jasmine-diff-reporter direct or indirect dependencies, so you might consider addressing this.

Affected dependencies:

hoek
timespan
tunnel-agent

@mradionov
Copy link
Owner

All these dependencies are karma dependencies and my reporter is a plugin for karma, there is no way I can drop karma from dependencies or switch it for something else.

Hopefully they will fix their deps soon

karma-runner/karma#2994
karma-runner/karma#2996

@ghost
Copy link
Author

ghost commented Jun 20, 2018

Right, appreciate the quick reply 👍

@mradionov
Copy link
Owner

karma-runner/karma#2994

In karma 3.0.0 all vulnerable dependencies have been fixed. As a result karma-jasmine-diff-reporter has 0 vulnerabilities now as a result of runing npm audit with the latest dependencies.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant