This repository has been archived by the owner on Jun 6, 2021. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 24
node-gyp < 4.0.0 has a vulnerability in the tar package dependency #87
Comments
Thanks for letting us know, we'll look into it asap. |
@MayhemYDG let's roll out https://dependabot.com/ on this repo. I don't have access but this will let us manage dependencies a bit better and automate some of the stuff for us. |
Merged
Well, opting for dependabot mostly cause it can create PRs for us and we'd just need to keep an eye on those instead. |
Thanks a lot for the prompt fix. 👍
…On 24 Apr 2019, 23:42 +0200, Hung Tran , wrote:
Well, opting for dependabot mostly cause it can create PRs for us and we'd just need to keep an eye on those instead.
—
You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub, or mute the thread.
|
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
You should consider upgrading to node-gyp version 4.0.0 which uses version 4.4.8 of the tar package and therefore it is patched.
nodejs/node-gyp@1456ef2
The text was updated successfully, but these errors were encountered: