dfrencham / ms-signalr-client

Unofficial package for the Microsoft SignalR client. Intented for comsumption with jspm.
21 stars 16 forks source link

Dependency vulnerability #16

Closed radziksh closed 5 years ago

radziksh commented 5 years ago

hi @dfrencham thanks for your efforts in writing this library and JFYI I found some vulnerability using the command yarn audit (we use yarn package manager), it seems that upgrading jquery to version 3 should fix this problem: screenshot_23

radziksh commented 5 years ago

ah, I see message in docs: If you need a version of the SignalR client with jQuery3 support, see Paul Giletich's fork. - ok I will try his fork.