cache-base icon indicating copy to clipboard operation
cache-base copied to clipboard

update depedency unset-value to latest version

Open shernaz opened this issue 3 years ago • 12 comments

#Issue: The unset-value [email protected] poses a vulnerability. https://security.snyk.io/vuln/SNYK-JS-UNSETVALUE-2400660

#Solution: Upgrade the package to the latest version to mitigate this vulnerability.

Please let me know if more information / explanation would be required.

shernaz avatar Apr 01 '22 11:04 shernaz

Can the maintainer please merge this in?

benjamindally avatar Oct 20 '22 15:10 benjamindally

@jonschlinkert Can this please be merged? The vulnerability on unset-value can be handled with this.

RodCardenas avatar Nov 03 '22 16:11 RodCardenas

@wtgtybhertgeghgtwtg Can you merge this?

RodCardenas avatar Nov 03 '22 19:11 RodCardenas

I am not a maintainer, so I cannot.

wtgtybhertgeghgtwtg avatar Nov 03 '22 20:11 wtgtybhertgeghgtwtg

it will be great if this get merge

krudos avatar Nov 16 '22 01:11 krudos

I am not a maintainer of this repo. Hence it is not possible to be of help. Apologies.

On Wed, 16 Nov 2022 at 07:00, krudos @.***> wrote:

it will be great if this get merge

— Reply to this email directly, view it on GitHub https://github.com/jonschlinkert/cache-base/pull/28#issuecomment-1316145973, or unsubscribe https://github.com/notifications/unsubscribe-auth/ACHBVSLV4YTCBIUDRZWVKDTWIQ2NHANCNFSM5SILJTCQ . You are receiving this because you authored the thread.Message ID: @.***>

shernaz avatar Nov 16 '22 12:11 shernaz

It appears @jonschlinkert has not done anything in Github since 2021. Not sure what that means, but he seems to not be maintaining a presence here any more. Seems like this is never going to be fixed unless there is some way he can grant someone else maintainer access or Github can. Does anyone know if there is a process for this? (I'm just sick of the constant warnings from Snyk when this could have been fixed 8 months ago).

skadz avatar Dec 14 '22 22:12 skadz

Reached out on Twitter to see if he can help us out.

https://twitter.com/skadz/status/1603162862393901058

skadz avatar Dec 14 '22 23:12 skadz

anyone got LinkedIn premium? He's on there and active

markkelsall avatar May 15 '23 14:05 markkelsall

Apparently @jonschlinkert is active on Github. Could you please merge this PR? Thanks!

victorpinheiro avatar Jun 09 '23 09:06 victorpinheiro

Can we please merge this PR?

sj5515139 avatar Jun 30 '23 07:06 sj5515139

👍🏻 for the merge

jpcmf avatar Oct 02 '23 17:10 jpcmf