secretyouth / react-datez

An easy to use, customizable mobile-friendly datepicker.
MIT License
126 stars 24 forks source link

Dependencies express` version security warning #43

Closed joemewes closed 5 years ago

joemewes commented 5 years ago

hi.

current express version is fixed at "4.14.1", which has a dep on fresh which has a Regular Expression Denial of Service security warning when running npm audit. FYI.

 Package       │ fresh                                                        │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ >= 0.5.2

is it possible to up the version of express or allow for ^minor updated versions of express/deps in package.json?

what's best?

can create a PR is needed. and thanks for the project... it's great!

secretyouth commented 5 years ago

Thanks to @kladess who fixed this. Release coming soon.