node-java
node-java copied to clipboard
Vulnerability in async dependency
Prototype Pollution in async dependency: https://github.com/advisories/GHSA-fwr7-v2mv-hh25
Please, upgrade it! Thanks!
+1
DependaBot opened a PR to get this fixed (#553 bumps async from 2.6.1 to 2.6.4). @joeferner Since this is a security issue, can this PR be merged and a new release created? Thanks.