-
-
Notifications
You must be signed in to change notification settings - Fork 1.5k
Closed
Description
# npm audit report
tmp <=0.2.3
tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter - https://github.com/advisories/GHSA-52f5-9888-hmc6
No fix available
node_modules/tmp
patch-package *
Depends on vulnerable versions of tmp
node_modules/patch-package
2 low severity vulnerabilities
Some issues need review, and may require choosing
a different dependency.
Metadata
Metadata
Assignees
Labels
No labels