Understanding that this package has been suffering from low maintainer resources, I thought it would be useful to raise alert as it looks some sort of vulnerability, which (possibly) could be dealt relatively easily by updating the dependencies.
additional info
I'm not very knowledgeable about the internal of this package, but after a quick look-over it looks like the version is locked here, which currently is preventing us from upgrading morgan upto its safe version.
Hope it helps!
Hi, first of all thanks really a lot for maintaining the package!
security alert
Just noticed github has been giving an alert for potential vulnerability on
morgan
, one of its dependencies.(datailed report here) https://nvd.nist.gov/vuln/detail/CVE-2019-5413
Understanding that this package has been suffering from low maintainer resources, I thought it would be useful to raise alert as it looks some sort of vulnerability, which (possibly) could be dealt relatively easily by updating the dependencies.
additional info
I'm not very knowledgeable about the internal of this package, but after a quick look-over it looks like the version is locked here, which currently is preventing us from upgrading morgan upto its safe version. Hope it helps!