-
Notifications
You must be signed in to change notification settings - Fork 155
Open
Labels
Description
I wanted to report some vulnerabilities that should be fixed before this package gets out of LTS.
Here's the list:
- Gravity: high, package:
minimatch, path:loopback-component-storage > pkgcloud > liboneandone > mocha > glob > minimatch, patched in:3.0.2 - Gravity: CRITICAL, package:
growl, path:loopback-component-storage > pkgcloud > liboneandone > mocha > growl, patched in:1.10.2 - Gravity: Low, package:
debug, patched in3.1.0 - Gravity: Moderate, package:
swagger-ui, fixed in3.20 - Gravity: Low, package:
minimist, patched in:1.2.3 - Gravity: High, package:
node-forge, patched in0.10.0
How to reproduce
npm audit will show the vulnerabilities.