ember-cli-addon-docs icon indicating copy to clipboard operation
ember-cli-addon-docs copied to clipboard

Security vulnerability: Update packages cryptiles and mime

Open tansongyang opened this issue 6 years ago • 0 comments

This project depends on vulnerable versions of cryptiles and mime.

Cryptiles: CVE-2018-1000620 Mime: CVE-2017-16138

It would probably also be a good idea to turn on automated checks for insecure dependencies.

Yarn resolutions may be helpful here. For us, pinning request to 2.87.0 seems to fix this (request is the source of the cryptiles and mime dependencies).

tansongyang avatar Mar 15 '19 14:03 tansongyang