-
Notifications
You must be signed in to change notification settings - Fork 756
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update localtunnel package to fix a vulnerable dependency - fixes #1695 #1697
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Merge it!
@@ -48,7 +48,7 @@ | |||
"fs-extra": "3.0.1", | |||
"http-proxy": "1.15.2", | |||
"immutable": "^3", | |||
"localtunnel": "1.9.1", | |||
"localtunnel": "1.9.2", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
"localtunnel": "1.9.2", | |
"localtunnel": "^1.9.2", |
How about adding a caret range? This would allow >=1.9.2 <2.0.0
.
https://yarnpkg.com/en/docs/dependency-versions#toc-caret-ranges
In any case, would be great to get this security issue released as soon as possible, pinned or careted.
Thanks!
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
If the maintainer(s) are okay with this change it sounds reasonable. What say @shakyShane ?
@gaards please merge. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM. Can we get this in?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The only difference from localtunnel 1.9.1 to 1.9.2 is the update of axios to 0.19.0 which has no breaking changes.
This merge looks good.
released in browser-sync@2.26.7 - thank you :) |
Updates the localtunnel package to the latest version that includes an updated version of the axios package (which contained a security vulnerability).
Related issue
#1695