Automattic / knox

S3 Lib
MIT License
1.74k stars 285 forks source link

chore(package): bump debug to 2.6.7 #321

Open faust64 opened 7 years ago

faust64 commented 7 years ago

prior to 2.6.7, debug pulls some known-to-be-vulnerable version of ms, according to Snyk https://snyk.io/test/npm/debug/2.6.6

Following up on https://github.com/Automattic/knox/pull/293, https://github.com/Automattic/knox/pull/300, https://github.com/Automattic/knox/pull/318

BrandonCopley commented 7 years ago

What can we do to merge this, as this relates to security concerns. It should be a REALLY simple pull and release to NPM. any chance of this happening?

faust64 commented 7 years ago

Merging would indeed be nice. Then again, previously-merged patches weren't pushed to npmjs, ... @BrandonCopley feel free to pull my fork instead: https://www.npmjs.com/package/myknox