paulmillr / chokidar

Minimal and efficient cross-platform file watching library
https://paulmillr.com
MIT License
10.8k stars 574 forks source link

Fixes for several vulnerabilities #1323

Closed AndrewCadeI closed 2 months ago

AndrewCadeI commented 2 months ago

Several vulnerabilities through referenced packages have been fixed. Previously npm reported the following:

12 vulnerabilities (1 low, 7 moderate, 1 high, 3 critical)

The main concern for me was Braces - https://security.snyk.io/vuln/SNYK-JS-BRACES-6838727 https://www.cve.org/CVERecord?id=CVE-2024-4068

Vulnerabilities now sit according to npm as 7 moderate severity vulnerabilities

paulmillr commented 2 months ago

learn the fucking manual

https://stackoverflow.com/questions/22343224/whats-the-difference-between-tilde-and-caret-in-package-json