foreversd / forever-monitor

The core monitoring functionality of forever without the CLI
MIT License
1.16k stars 178 forks source link

vulnerability in minimist #193

Closed gaonkar18y closed 4 years ago

gaonkar18y commented 4 years ago

We get below vulnerability during npm audit

Package minimist
Patched in >=0.2.1 <1.0.0 || >=1.2.3
Dependency of forever-monitor
Path forever-monitor > broadway > nconf > optimist > minimist

I can see that the version of 'broadway' is very old i.e "~0.3.6".

Can you please make required changes to fix this vulnerability.

Thanks in advance for any help.

kibertoad commented 4 years ago

Released in forever-monitor 3.0.2 and forever 3.0.3.