node-ffi-napi / ref-napi

Turn Buffer instances into "pointers"
MIT License
123 stars 68 forks source link

node-addon-api vulnerability reported, upgrade to v2.0.1 or higher #38

Open RMutharaju opened 4 years ago

RMutharaju commented 4 years ago

Hello,

I see a vulnerability reported with node-addon-api

Refer: https://snyk.io/vuln/SNYK-JS-NODEADDONAPI-571001

Kindly upgrade the node version as proposed.

Thanks.

RMutharaju commented 4 years ago

Is there any plan to update the node to use higher version of node-addon-api soon?

addaleax commented 4 years ago

This package is not affected by the linked vulnerability. If you want to open a PR to update the dependency, go ahead.