winstonjs / node-loggly

A client implementation for Loggly in node.js
http://github.com/winstonjs/node-loggly
Other
233 stars 80 forks source link

Loosen semver ranges #79

Closed wheresrhys closed 5 years ago

wheresrhys commented 6 years ago

request 2.75.0 depends, via a few different dependency chains, on hoek, which is flagged as a moderate security risk by npm audit. Widening the semver range for request allows the latest version of hoek - which patches the security flaw - to be picked up. I've also widened the other semver ranges in your dependencies to improve the library's ability to pick up security patches automatically.