Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix "potential" vulnerability in our dev deps #2584

Closed
etpinard opened this issue Apr 27, 2018 · 3 comments
Closed

Fix "potential" vulnerability in our dev deps #2584

etpinard opened this issue Apr 27, 2018 · 3 comments

Comments

@etpinard
Copy link
Contributor

etpinard commented Apr 27, 2018

From https://github.com/plotly/plotly.js/network/dependencies

image

where pkg hoek is the culprit.

From the package-lock file on master on April 27, 2018, we have:

image

where bumping our direct dev-dependencies karma, jsdom and node-sass does not solve the issue. We'll most likely have to wait for request/request#2875 or a similar PR to be merged.

@etpinard
Copy link
Contributor Author

Looks like hoek no longer shows up as vulenerable on https://github.com/plotly/plotly.js/network/dependencies

image

Closing.

@Romick2005
Copy link

Installed today recent version of plotly.js. And npm found 4 vulnerabilities:
https://www.screencast.com/t/vfvTWRY87yZO

@etpinard
Copy link
Contributor Author

@Romick2005 see #2386 (comment)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants