Skip to content

Conversation

illandril
Copy link
Contributor

This would resolve #1343 by removing update-notifier entirely.

Since most will have some other way of detecting when they have outdated dependencies, having json-server itself notify when there is an update is probably not worth the effort that would be required to keep that functionality while still removing the vulnerability.

@typicode typicode merged commit bd3fa55 into typicode:master Nov 3, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update update-notifier to resolve got vulnerability CVE-2022-33987

2 participants