Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

(security alert) morgan needs to be updated #1136

Open
fursich opened this issue Mar 26, 2019 · 0 comments
Open

(security alert) morgan needs to be updated #1136

fursich opened this issue Mar 26, 2019 · 0 comments

Comments

@fursich
Copy link

fursich commented Mar 26, 2019

Hi, first of all thanks really a lot for maintaining the package!

security alert

Just noticed github has been giving an alert for potential vulnerability on morgan, one of its dependencies.

(datailed report here)
https://nvd.nist.gov/vuln/detail/CVE-2019-5413

Understanding that this package has been suffering from low maintainer resources, I thought it would be useful to raise alert as it looks some sort of vulnerability, which (possibly) could be dealt relatively easily by updating the dependencies.

additional info

I'm not very knowledgeable about the internal of this package, but after a quick look-over it looks like the version is locked here, which currently is preventing us from upgrading morgan upto its safe version.
Hope it helps!

@fursich fursich changed the title (security alert) updated morgan (security alert) morgan needs to be updated Mar 26, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant