-
Notifications
You must be signed in to change notification settings - Fork 261
Open
Description
The latest version of "he" contains some vulnerabilities according to "npm audit":
26 vulnerabilities (8 moderate, 9 high, 9 critical)
I'm not using this package directly but instead it is being referenced through mocha (and I'm using mocha). But I'm just seeing if this project is active enough that perhaps these vulnerabilities will be addressed at some point. I'm certainly no expert with this but it appears that the vulnerabilities are related to packages that need upgrading to newer versions.
I think just having newer packages that update the lodash version will satisfy my vulnerability scanner.
ninest
Metadata
Metadata
Assignees
Labels
No labels