-
Notifications
You must be signed in to change notification settings - Fork 91
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update rimraf (CWE-772) #506
Comments
1 task
@w3nl let's just drop Node 12 support and pick a minimum engine that supports |
@w3nl want to update your CL accordingly, I can merge after. |
@bcoe |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Linux tux 6.5.0-14-generic #14-Ubuntu SMP PREEMPT_DYNAMIC Tue Nov 14 14:59:49 UTC 2023 x86_64 x86_64 x86_64 GNU/Linux
(Ubuntu 23.10)Rimraf is outdated, and because C8 use an old version, we receive vulnerability issues.
Inflight has a CWE issue, that is an indirect dependency of this package.
rimraf@3.0.2 › glob@7.2.3 › inflight@1.0.6
https://security.snyk.io/vuln/SNYK-JS-INFLIGHT-6095116
https://cwe.mitre.org/data/definitions/772.html
In rimraf 4 this is already solved, by removing glob as a dependency:
https://github.com/isaacs/rimraf/blob/main/CHANGELOG.md
The text was updated successfully, but these errors were encountered: