rubenv / grunt-git

Git commands for grunt.
MIT License
227 stars 83 forks source link

Indirect underscore.string 2.x dependency vulnerable #141

Closed mwri closed 5 years ago

mwri commented 5 years ago

Indirect dependency on underscore.string ^2.3.3 and 2.x is subject to vulnerability https://www.npmjs.com/advisories/745.

Upgrading dependency to flopmang ^1.0.0 fixes this.