Skip to content

Conversation

@adamenveil
Copy link

licensee is currently using a very old version of @npmcli/arborist, which pulls in a vulnerable version of glob.

GHSA-5j98-mcp5-4vw2

Bumping arborist to the latest version, 9.1.7

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant