Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix #108 - Bumping up mkdirp version to 0.5.5 #109

Merged
merged 1 commit into from
Jul 29, 2020

Conversation

LostInBrittany
Copy link
Contributor

@LostInBrittany LostInBrittany commented Jul 20, 2020

Hi!

I see that in PR #101 you bumped-up the version of mkdirp to 0.5.5 which in turn updates minimist to 1.2.5
which addresses https://www.npmjs.com/advisories/1179

Problem is that this PR only updated package-lock.json and not package.json that remains at 0.5.1. As package.json still depends on mkdirp 0.5.1, when we get node-portfinder as a dependency, we still get an old version of minimist.

@LostInBrittany
Copy link
Contributor Author

I didn't understand why Travis failed, as it didn't fail on my fork. So I closed the PR and reopened it to force a new Travis check, and it passed 👍

@eriktrom eriktrom merged commit 6fbe05e into http-party:master Jul 29, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants