mapbox / dyno

simple dynamodb client
MIT License
78 stars 31 forks source link

Depends on compromised package "event-stream" #145

Closed repl-sean-heintz closed 5 years ago

repl-sean-heintz commented 5 years ago

https://github.com/dominictarr/event-stream/issues/116

This package depends on a compromised package, event-stream. Can you please update it to use a different library?

freemcclure commented 5 years ago

The fix should involve only allowing event-stream 3.3.4 as per a suggestion here: https://github.com/dominictarr/event-stream/issues/115