runem / lit-analyzer

Monorepository for tools that analyze lit-html templates
MIT License
318 stars 36 forks source link

Security vulnerabilities in dependencies and generally outdated dependencies #226

Closed mohe2015 closed 2 years ago

mohe2015 commented 2 years ago

https://github.com/runem/lit-analyzer/blob/56489d04242b35d692b1db4d0f776f9ca0da19b9/packages/lit-analyzer/package.json#L47 is an old version of fast-glob that depends on the vulnerable version of glob-parent see https://github.com/advisories/GHSA-ww39-953v-wcq6.

Please update this dependency specifically and I think dependencies should be more up-to-date in general.