Thinkmill / manypkg

☔️ An umbrella for your monorepo
MIT License
884 stars 48 forks source link

Remove vulnerable package meow #90

Closed jroebu14 closed 3 years ago

jroebu14 commented 3 years ago

Removes package meow from @manypkg/cli. The meow package contains a vulnerable package hosted-git-info@2.8.8

Introduced through: @manypkg/cli@0.17.0 › meow@6.1.1 › normalize-package-data@2.5.0 › hosted-git-info@2.8.8

More info here: https://app.snyk.io/test/npm/@manypkg/cli/0.17.0#SNYK-JS-HOSTEDGITINFO-1088355

It appears to me that meow is not used anywhere in the codebase so it made sense to remove this package rather than upgrade it to a safe version.

changeset-bot[bot] commented 3 years ago

🦋 Changeset detected

Latest commit: 89c9ae99cd6ac6958ca8622a5f259295c88bb28e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package | Name | Type | | ------------ | ----- | | @manypkg/cli | Patch |

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR