serverless / serverless-kubeless

This plugin enables support for Kubeless within the Serverless Framework.
Apache License 2.0
303 stars 80 forks source link

Update dependencies #129

Closed RaeesBhatti closed 6 years ago

RaeesBhatti commented 6 years ago

There are known vulnerabilities in version of two of the packages we're using: night-growl@1.9.2 and UglifyJS2@1.3.5.

andresmgot commented 6 years ago

Hi @raeesbhatti, can you clarify what are the security vulnerabilities and which packages depends of night-growl and uglifyjs? I am saying this because:

andresmgot commented 6 years ago

@raeesbhatti I opened #130 updating just sinon that was the culprit of installing uglify-js. With that I see that we are not installing any of the vulnerable packages you mention.

andresmgot commented 6 years ago

Closing this PR since #130 is merged and released. Thanks for reporting the issue @raeesbhatti !

RaeesBhatti commented 6 years ago

Thanks for fixing this @andresmgot 👍