Graphcool / graphcool-framework

Apache License 2.0
1.78k stars 130 forks source link

Vulnerability in dependency #433

Open marktani opened 6 years ago

marktani commented 6 years ago

Issue by dyst5422 Thursday Dec 07, 2017 at 22:07 GMT Originally opened as https://github.com/graphcool/prisma/issues/1373


There seems to be a vulnerability with using a relatively old version of a dependency.

screen shot 2017-12-07 at 2 03 38 pm

Traced it back to graphcool

graphcool@0.10.1 -> graphcool-cli-core@1.8.0 -> download-github-repo@0.1.3 -> download@0.1.19 -> decompress@0.2.5 -> tar@0.1.20