Closed kinueng closed 4 years ago
Updated the description with the latest npm audit
results.
The braces dependency is coming from our use of dustjs-linkedin@2.7.5. That is the latest version of the module. If we need to remove the vulnerability, then we will have to move away from using dust or find a new module to handle our dust templates.
On my system it's pulling http-proxy-middleware 0.17.4 which is using a braces version >2.3.1.