postmanlabs / curl-to-postman

Converts curl requests to Postman Collection v2 request objects
Apache License 2.0
65 stars 31 forks source link

Vulnerable dependency with shell-quote version 1.6.1 #50

Open Rafo1994 opened 2 years ago

Rafo1994 commented 2 years ago

Hi,

version 1.1.1 depends on shell-quote package version 1.6.1 which has critical vulnerability (command injection, more here https://github.com/advisories/GHSA-g4rg-993r-mgx7). That issue was fixed with shell-quote version 1.7.3.

Thanks :)