scarney81 / pg-hstore

A node package for serializing and deserializing JSON data to hstore format
MIT License
105 stars 21 forks source link

Critical vulnerabilities #27

Open canogluonur opened 8 months ago

canogluonur commented 8 months ago

Hi,

I use the pg-hstore package from my code. I did a scan in my code with Trivy and it said to me:

image

do you fixed underscore's version 1.12.1

elawad commented 4 months ago

I had the same question. Looks like it's fixed in pg-hstore@2.3.4. https://github.com/scarney81/pg-hstore/blob/4f4530f82920f81fee3eda1d5c3600ca3598b280/package.json#L23