You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
dot-prop at 5.1.0 and earlier is subject to CVE-2020-8116:
Prototype pollution vulnerability in dot-prop npm package version 5.1.0 and earlier allows an attacker to add arbitrary properties to JavaScript language constructs such as objects.
This is resolved in npm-check-updates in version 4. I've made PR #40 as a speculative fix.
The text was updated successfully, but these errors were encountered:
dot-prop
is pulled in to this module by the dependency chain[email protected] > [email protected] > [email protected] > [email protected] > dot-prop@^4.1.0
.dot-prop
at 5.1.0 and earlier is subject to CVE-2020-8116:This is resolved in
npm-check-updates
in version 4. I've made PR #40 as a speculative fix.The text was updated successfully, but these errors were encountered: