@bscofield @isaacs Can you please mark the 2.8.9 release as actually fixing the vuln too? https://www.npmjs.com/advisories/1677 This is started to trickle downstream: https://github.com/npm/normalize-package-data/issues/120 Here is the proof, in case anyone needs it: https://github.com/npm/hosted-git-info/compare/v2.8.8...v2.8.9