TooTallNate / node-degenerator

Turns sync functions into async functions
20 stars 17 forks source link

Critical vulnerability in vm2 dependency #15

Closed toastyghost closed 2 years ago

toastyghost commented 2 years ago

Just got this from Snyk:

vm2-vuln

Fix is straightforward, just update the package and republish

robdmoore commented 2 years ago

For some reason I'm not able to use npm-force-resolutions to force this dependency to upgrade like I normally would.

This is a deep depedency of (I'm sure many other libraries too) aws-cdk.

Any chance the PR can get merged and released given the criticality of this vulnerability @TooTallNate 🙏?

robdmoore commented 2 years ago

Thanks @TooTallNate!