You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Chore summary
The @stoplight/spectral-cli package has an indirect dependency on optionator v0.9.1, which has a vulnerability (CVE-2023-26115) due to its "word-wrap" dependency. Optionator v0.9.3 was recently released which fixes this by using a different "word-wrap" package.
The purpose of this issue is to request that spectral-cli be updated to avoid this CVE.
Tasks
Upgrade dependencies so that optionator v0.9.3 is used in order to avoid CVE-2023-26115
Additional context
n/a
The text was updated successfully, but these errors were encountered:
Chore summary
The @stoplight/spectral-cli package has an indirect dependency on optionator v0.9.1, which has a vulnerability (CVE-2023-26115) due to its "word-wrap" dependency. Optionator v0.9.3 was recently released which fixes this by using a different "word-wrap" package.
The purpose of this issue is to request that spectral-cli be updated to avoid this CVE.
Tasks
Additional context
n/a
The text was updated successfully, but these errors were encountered: