Skip to content

Upgrade mkdirp 0.5.1 -> 0.5.3 to resolve minimist vulnerability #86

Closed
@prios-ben-beckerman

Description

@prios-ben-beckerman

The dependency mkdirp is pinned to 0.5.1. Mkdirp 0.5.1 has its own pinned dependency, minimist 0.0.8, which has a vulnerability. extract-zip should be upgraded to use mkdirp 0.5.3 which uses a newer version of minimist.

See isaacs/node-mkdirp#7

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions