google / traceur-compiler

Traceur is a JavaScript.next-to-JavaScript-of-today compiler
Apache License 2.0
8.17k stars 580 forks source link

update semver dependency to ^4.3.2 #2060

Closed krugar closed 8 years ago

krugar commented 8 years ago

there exists a denial-of-service security advisory for the version of semver used in traceur@0.0.93:

https://nodesecurity.io/advisories/31 https://snyk.io/vuln/npm:semver:20150403

suggested remedy is to use semver@^4.3.2