alanshaw / david-www

:eyeglasses: David helps keep your Node.js project dependencies up to date.
https://david-dm.org
MIT License
729 stars 131 forks source link

Superagent dependency 3.7.0 still marked as vulnerable #389

Closed jkutianski closed 6 years ago

jkutianski commented 6 years ago

I updated Superagent to 3.7.x on my package but it's still marked as vulnerable on https://david-dm.org/jkutianski/meetup-api

alanshaw commented 6 years ago

At a guess I'd say the advisory had a typo with the vulnerable versions that was updated after it was published. David doesn't automatically update advisories info it already knows about. I've restarted the service (which clears the advisories cache) and your dependency is now showing as not vulnerable.

HTH

jkutianski commented 6 years ago

Thanks Alan. Now it;s OK.