gotwarlost / istanbul

Yet another JS code coverage tool that computes statement, line, function and branch coverage with module loader hooks to transparently add coverage when running tests. Supports all JS coverage use cases including unit tests, server side functional tests and browser tests. Built for scale.
Other
8.7k stars 786 forks source link

Async package is vulnerable #949

Open 0xhmn opened 2 years ago

0xhmn commented 2 years ago

It seems this this package uses async@1.5.2 which npm audit considers it as High severity.

└─┬ solidity-coverage@0.7.21
  └─┬ sc-istanbul@0.4.6
    └── async@1.5.2