Skip to content

[QUESTION] Possible to fix vulnerability issue related to dot-prop? #1560

@ziale

Description

@ziale

What / Why

Anchore is reporting a vulnerability issue that is related to an old(<5.1.1) version of the dot-prop package.

I tried to trace the versions:
update-notifier depends on configstore which depends on dot-prop.

[email protected] uses [email protected] which uses [email protected] where the issue has been fixed.

Is it possible to fix this?

Metadata

Metadata

Assignees

No one assigned

    Labels

    Awaiting Informationfurther information is requestedRelease 6.xwork is associated with a specific npm 6 release

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions