Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade debug to v2.6.9 #13

Closed
joseluisq opened this issue Dec 15, 2017 · 9 comments
Closed

Upgrade debug to v2.6.9 #13

joseluisq opened this issue Dec 15, 2017 · 9 comments

Comments

@joseluisq
Copy link

joseluisq commented Dec 15, 2017

Actually pino-debug@1.0.5 uses debug@2.6.0, because of this security vulnerability an upgrade of debug to v2.6.9 should fix it.

Update: it's already done at b892b08

@joseluisq
Copy link
Author

Note: That issue is already fixed in v2.6.9

Refs: debug-js/debug#504

@joseluisq joseluisq changed the title Upgrade debug to v3 or greater Upgrade debug to v2.6.9 or greater Dec 15, 2017
@mcollina
Copy link
Member

I am a bit lost. What are you proposing apart from #11?

@joseluisq
Copy link
Author

I am a bit lost. What are you proposing apart from #11?

#11 is not my PR. I purpose only the upgrading of that dependency, because I'm using pino-debug@1.0.5. But I saw the pino-debug is not compatible with debug v3

@joseluisq
Copy link
Author

joseluisq commented Dec 15, 2017

Anyway, an anticipated upgrade of debug to v2.6.9 it would be more logic. correct me if wrong.

@joseluisq
Copy link
Author

v1.0.5: https://unpkg.com/pino-debug@1.0.5/package.json (debug v2.6.0)
Master: debug v2.6.9 (b892b08)

package.json on master branch contains debug v2.6.9

@joseluisq joseluisq changed the title Upgrade debug to v2.6.9 or greater Upgrade debug to v2.6.9 Dec 15, 2017
@mcollina
Copy link
Member

I’m still lost. What do you want us to do? Is the release on npm not in sync to what is on master?

@joseluisq
Copy link
Author

joseluisq commented Dec 15, 2017

yep, basically bump up a new pino-debug release with debug v2.6.9

@mcollina
Copy link
Member

Released v1.0.6.

@joseluisq
Copy link
Author

👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants