DavidTanner / nodecredstash

MIT License
43 stars 22 forks source link

Allow upgraded dependency to pickup security fixes #24

Closed mdlavin closed 6 years ago

mdlavin commented 6 years ago

Upstream projects often release fixes for security vulnerabilities. Specifically, the aws 2.171.0 version is affected by https://snyk.io/vuln/npm:crypto-browserify:20140722 and the newer versions have a fix for it.

mdlavin commented 6 years ago

@DavidTanner is there anything I can do to make you more comfortable merging this? I'd love to pickup the security fixes in my projects

mdlavin commented 6 years ago

@DavidTanner Thank you! I'll keep an eye out for a new published version

DavidTanner commented 6 years ago

This is deployed as 2.0.2