-
Notifications
You must be signed in to change notification settings - Fork 2.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
security: update minimist and geojson-rewind to avoid CVE-2021-44906 #12442
security: update minimist and geojson-rewind to avoid CVE-2021-44906 #12442
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good to me, thanks @Spasfonx!
Sorry, missed that the PR was made to the |
Thanks for your review ! Watch out, this fix apply only for old versions (1.x.x), I pointed at |
stepankuzmin we reply at the same time héhé. Indeed it was my intent, the main update here for security is through |
I see, thanks! Thanks for the contribution, but I'll close this PR since it doesn't affect the users. Sorry for the confusion. |
Ah, so there is a security alert when you use the 1.x version? We should update it then. |
Hello there, happy new year everyone ! 🎉 Some news on this update ? |
The changes looks good to me too. 👍 Well done @Spasfonx 🎉 |
Happy new year all and thanks for the PR @Spasfonx ! 🎉 Also looks good to me! Though, we may want to make a new branch for the release. We're aiming to get a release with the update out next week. |
Oh great ! Thanks you very much guys 💪 |
Thanks, everyone! This is now fixed in the v1.13.3 release. |
Thank you guys, perfect ! 🙏 |
Update dependencies on old versions of mapbox-gl-js (1.13.2) to avoid GHSA-xvch-5gv4-984h issue.
Edit: This fix is for old version of
mapbox-gl-js
(1.3.2
)