bower / bower

A package manager for the web
bower.io
MIT License
14.99k stars 1.85k forks source link

Update "minimist" dependency in bower-config #2616

Open chergott opened 2 years ago

chergott commented 2 years ago

bower-config package currently uses minimist ^0.2.1 which has a Prototype Pollution vulnerability

minimist 1.2.6 addresses this vulnerability

Additional information: NVD: https://nvd.nist.gov/vuln/detail/CVE-2020-7598 Vulnerability: https://snyk.io/vuln/npm%3Aminimist