Skip to content

Conversation

@kasicka
Copy link

@kasicka kasicka commented Apr 8, 2021

Fixes CVE-2021-27290

References

@kasicka kasicka requested a review from a team as a code owner April 8, 2021 10:40
@wraithgar wraithgar added the Release 6.x work is associated with a specific npm 6 release label Apr 8, 2021
@ruyadorno
Copy link
Contributor

hi @kasicka thanks for the contribution!

We usually manage dependency updates as part of our release process. That said, you don't need to worry about submitting a PR with those and they should be included in the next v6.x update! 😊

@ruyadorno ruyadorno closed this Apr 8, 2021
@kasicka
Copy link
Author

kasicka commented Apr 9, 2021

@ruyadorno hello, thank you for letting me know, I would hope that that is the case. Normally I would not send a PR, but I wanted to make sure you are aware of the CVEs and they get fixed, I kinda got inspired by the latest Node.js security release and #2737

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Release 6.x work is associated with a specific npm 6 release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants