kelektiv / node.bcrypt.js

bcrypt for NodeJs
MIT License
7.43k stars 510 forks source link

Version bump, security updates to sub dep npmlog #905

Closed adaniels-parabol closed 2 years ago

jannomeister commented 2 years ago

can the maintainers approve this PR? because snyk detected a CVE in the latest version of bcrypt

alias-mac commented 2 years ago

@jannomeister the dependency is using a ^, thus you should be able to bump the version to latest in your own parent dependency. What am I missing?