watson / bonjour

A Bonjour/Zeroconf protocol implementation in JavaScript
MIT License
627 stars 146 forks source link

Vulnerability in package #68

Open PabloJomer opened 3 years ago

PabloJomer commented 3 years ago

https://github.com/watson/bonjour/blob/bdc467a4f3c7b9fe8bc54468b6fc4d80b8f1c098/package.json#L11

The marked lib has a transient dep to a vulnerable package which has been fixed. Is it possible to upgrade to a later version like "^7.0.0"