Closed austinbrown-okta closed 3 years ago
The current version of node-pre-gyp is vulnerable to CVE-2020-7598 via inclusion of a vulnerable minimist version. This PR patches the vuln by upgrading node-pre-gyp from 0.14.0 to 0.17.0.
node-pre-gyp
minimist
References:
Thanks. Why I don't see how it does impact this library in any way, I guess we have to move forward.
The current version of
node-pre-gyp
is vulnerable to CVE-2020-7598 via inclusion of a vulnerableminimist
version. This PR patches the vuln by upgradingnode-pre-gyp
from 0.14.0 to 0.17.0.References:
node-pre-gyp
changelog: https://github.com/mapbox/node-pre-gyp/blob/master/CHANGELOG.md