-
-
Notifications
You must be signed in to change notification settings - Fork 603
Closed
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency file
Description
CVE-2021-35065 only applies to glob-parent 5.1.1 and 6.0.0, it does not apply to 5.1.2 which we are using. glob-parent 5.1.2 is not vulnerable. We will not update to 6.0 because chokidar 3 needs to support nodejs v8.
If your tool tells you chokidar is vulnerable, report issues to your build tool. White Source Software is particular piece of shit since it does not do proper checks.
zorcec, anders8, 213edu and AndreyYolkindzzk, Techie-Pi, keenwon, 0x2b3bfa0, mateuscruz and 9 more
Metadata
Metadata
Assignees
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency file