Closed akoumany closed 1 year ago
Hi there @cameronhunter
Huge thanks for putting this together. Dependabot found a vulnerability in underscore@~1.6.0 via a transitive dependency on nomnom@1.8.1.
underscore@~1.6.0
nomnom@1.8.1
I see that nomnom is 10 years old and unmaintained, any plans to update packages?
If not, do you have time to review and merge a fix if I put in the work?
I've removed the dependency on nomnom in v2.0.0
nomnom
v2.0.0
Hi there @cameronhunter
Huge thanks for putting this together. Dependabot found a vulnerability in
underscore@~1.6.0
via a transitive dependency onnomnom@1.8.1
.I see that nomnom is 10 years old and unmaintained, any plans to update packages?
If not, do you have time to review and merge a fix if I put in the work?