Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix: Upgrading Vulnerable set-value Package #12

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

loChris
Copy link

@loChris loChris commented Sep 17, 2021

Updating set-value version from 3.0.0 to 4.1.0 since the v3 has a security vulnerability.

CVE-2021-23440

@abdulgit2021
Copy link

@jonschlinkert, @doowb can you please review and merge this PR. it helps in resolving vulnerability

@jonschlinkert
Copy link
Owner

Apologies, I'm trying to spend more time on open source lately, I'll do this ASAP.

@nmccready
Copy link

@jonschlinkert any ETA?

@jonschlinkert
Copy link
Owner

jonschlinkert commented Oct 8, 2021 via email

@martinmckenna
Copy link

still need this @jonschlinkert. There's quite a bit of packages that use this and subsequently also have security vulnerabilities

@shanbady
Copy link

shanbady commented Nov 9, 2021

@jonschlinkert any update on this? We are also waiting on this upstream change.

@matrunchyk
Copy link

Just a humble reminder on this issue

@matrunchyk
Copy link

One more reminder, please @jonschlinkert :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

7 participants