Skip to content
This repository has been archived by the owner on Feb 15, 2022. It is now read-only.

[BUG] Upgrade transitive dependency "hosted-git-info@2.8.8" to fix CVE-2021-23362 #53

Open
bhamail opened this issue Mar 30, 2021 · 0 comments

Comments

@bhamail
Copy link

bhamail commented Mar 30, 2021

What / Why

While scanning my project with auditjs, I discovered read-installed has a transitive dependency on hosted-git-info@2.8.8 which has vulnerability CVE-2021-23362.

$ npm ls hosted-git-info
  auditjs@4.0.25 /Users/bhamail/sonatype/community/auditjs/auditjs
  └─┬ read-installed@4.0.3
    └─┬ read-package-json@2.1.2
      └─┬ normalize-package-data@2.5.0
        └── hosted-git-info@2.8.8
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant