-
Notifications
You must be signed in to change notification settings - Fork 944
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
please release a 1.0.5 that updates ms to v2.0.0 #469
Comments
Please see v1.0.5. |
Thank you! |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
debug 1.x is widely depended on still, and its getting flagged over and over for bringing in older versions of
ms
that had security vulnerabilities reported against it.Its a false positive, but a whole lot of build chains and users of debug, directly or indirectly, would be very, very, appreciative if you release a 1.x update to
debug
that uses the same version ofms
you use in master,2.0.0
. Its API compatible with thems
used now for 1.x, at least for the humanize calldebug
makes (the incompatibility - and the vulnerability - is around a parse function thatdebug
doesn't use).I can't PR the change because I'd need a 1.x branch to target, but its this:
The text was updated successfully, but these errors were encountered: