Skip to content

Bumped versions of vulnerable packages from npm #179

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Conversation

daniel-mueller
Copy link

Hi,
I was just browsing through your repos and found outdated, vulnerable versions of npm packages. I thought I could just leave you a PR with bumped versions.

Cheers

@arcticicestudio
Copy link
Contributor

arcticicestudio commented Oct 1, 2019

Hi @daniel-mueller 👋, thanks for your contribution 👍
GitHub's new security features are absolutely fantastic for the open source community, but in most cases it's not necessary to update on each notification (weakly reports are send as email too) so that's why many of my repositories are not updated directly. There's an overview of currently affected CVE's on the “security” repository tab as well as regular notifications in the inbox of maintainers.

gh-179-sec_tab-cves

Both vulnerabilities are not critical for nord-docs since axios is not used with the maxContentLength option and lodash only affects server-side environments.

Anyway, every contribution is always welcome and even more so for Hacktoberfest 😄
I'll merge your PR before the next regular dependency update to prevent merge conflicts with the package-lock.json.

@arcticicestudio arcticicestudio self-assigned this Oct 1, 2019
@arcticicestudio arcticicestudio self-requested a review October 1, 2019 17:47
@arcticicestudio arcticicestudio deleted the branch nordtheme:develop September 25, 2022 10:33
@svengreb
Copy link
Member

svengreb commented Sep 25, 2022

I'll restore your PR later on since it was closed automatically because the develop branch has been deleted through #229.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants