Skip to content
This repository has been archived by the owner on Oct 4, 2020. It is now read-only.

os-locale dependency vulnerable #168

Open
mcandre opened this issue Nov 3, 2019 · 1 comment
Open

os-locale dependency vulnerable #168

mcandre opened this issue Nov 3, 2019 · 1 comment

Comments

@mcandre
Copy link

mcandre commented Nov 3, 2019

Please update the os-locale dependency in order to resolve a vulnerability in mem.

sindresorhus/memoize@da4e439

https://www.npmjs.com/package/os-locale

@mcandre
Copy link
Author

mcandre commented Nov 3, 2019

Ah, I had mistakenly calculated the wrong source for this dependency. Looks like eclint updated os-locale and mem a while ago.

GitHub reporting does not provide the dependency chain. In fact, my old mem version is coming from eclint's version of gulp-reporter.

Please update or replace gulp-reporter.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant