Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update package package-json to remove vulnerability from got package #194

Open
mkszepp opened this issue May 26, 2024 · 0 comments
Open

Comments

@mkszepp
Copy link

mkszepp commented May 26, 2024

The package-json package on this addon is outdated and should be updated.

package-json v6 brings as dependency got v9 which has a vulnerability.

Updating the version package-json to v8 or newer removes in any addon which is using ember-try this vulnerability.
This update will be braking, because package-json has dropped node version (< v18)

See:
GHSA-pfrx-2q88-qq97

@mkszepp mkszepp changed the title Package package-json needs update to remove vulnerability from got package Update package package-json to remove vulnerability from got package May 26, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant