segment-boneyard / nightmare

A high-level browser automation library.
https://open.segment.com
19.54k stars 1.08k forks source link

Security vulnerability with deep-defaults dependency #1675

Open joshua-holmes opened 4 months ago

joshua-holmes commented 4 months ago

Hello, there is a CVE open for a security vulnerability in deep-defaults up to and including v1.0.5, which is the latest version. The deep-defaults npm page states that the project is deprecated and shows a message from the author, "not actively maintained; find alternatives." Since deep-defaults is no longer maintained and has a security vulnerability, it should be swapped out.