gulpjs / gulp-cli

Command Line Interface for gulp.
MIT License
401 stars 106 forks source link

Prototype Pollution [High Severity] in copy-props@2.0.4 #231

Closed mejiaj closed 3 years ago

mejiaj commented 3 years ago

A vulnerability with high severity has been reported from Snyk in our project. Here's the report:

Issues with no direct upgrade or patch: ✗ Prototype Pollution [High Severity][https://snyk.io/vuln/SNYK-JS-COPYPROPS-1082870] in copy-props@2.0.4 introduced by gulp@4.0.2 > gulp-cli@2.3.0 > copy-props@2.0.4

Please let me know if there's anything I forgot to include.