jonschlinkert / cache-base

Basic object store with methods like get/set/extend/omit
MIT License
56 stars 19 forks source link

update depedency unset-value to latest version #28

Open shernaz opened 2 years ago

shernaz commented 2 years ago

Issue:

The unset-value package@1.0.0 poses a vulnerability. https://security.snyk.io/vuln/SNYK-JS-UNSETVALUE-2400660

Solution:

Upgrade the package to the latest version to mitigate this vulnerability.

Please let me know if more information / explanation would be required.

benjamindally commented 2 years ago

Can the maintainer please merge this in?

RodCardenas commented 1 year ago

@jonschlinkert Can this please be merged? The vulnerability on unset-value can be handled with this.

RodCardenas commented 1 year ago

@wtgtybhertgeghgtwtg Can you merge this?

wtgtybhertgeghgtwtg commented 1 year ago

I am not a maintainer, so I cannot.

krudos commented 1 year ago

it will be great if this get merge

shernaz commented 1 year ago

I am not a maintainer of this repo. Hence it is not possible to be of help. Apologies.

On Wed, 16 Nov 2022 at 07:00, krudos @.***> wrote:

it will be great if this get merge

— Reply to this email directly, view it on GitHub https://github.com/jonschlinkert/cache-base/pull/28#issuecomment-1316145973, or unsubscribe https://github.com/notifications/unsubscribe-auth/ACHBVSLV4YTCBIUDRZWVKDTWIQ2NHANCNFSM5SILJTCQ . You are receiving this because you authored the thread.Message ID: @.***>

skadz commented 1 year ago

It appears @jonschlinkert has not done anything in Github since 2021. Not sure what that means, but he seems to not be maintaining a presence here any more. Seems like this is never going to be fixed unless there is some way he can grant someone else maintainer access or Github can. Does anyone know if there is a process for this? (I'm just sick of the constant warnings from Snyk when this could have been fixed 8 months ago).

skadz commented 1 year ago

Reached out on Twitter to see if he can help us out.

https://twitter.com/skadz/status/1603162862393901058

markkelsall commented 1 year ago

anyone got LinkedIn premium? He's on there and active

victorpinheiro commented 1 year ago

Apparently @jonschlinkert is active on Github. Could you please merge this PR? Thanks!

sj5515139 commented 1 year ago

Can we please merge this PR?

jpcmf commented 1 year ago

👍🏻 for the merge