-
Notifications
You must be signed in to change notification settings - Fork 243
Open
Labels
Description
Hey 👋 I notice its been a while since a new version of node-static has been pushed to NPM, and the version that currently exists there contains the package minimist which has a (github advisory) for it. This package was being used which is used by a package in this project called optimist. In this pull request, @brettz9 removed optimist to resolve this vulnerability. As a result, publishing a new version of node-static will ensure that all users of this package will use a safe version by default.
cc @cloudhead
cloudhead, kohakukun, blaasvaer, cs8425, rossjones and 12 more