yeun / open-color

Color scheme for UI design.
https://yeun.github.io/open-color/
MIT License
5.29k stars 242 forks source link

Arbitrary File Overwrite - 1.7.0 Open Color #98

Closed Subwaytime closed 4 years ago

Subwaytime commented 5 years ago

Hey there, so i am running into some NPM Audit Errors for "fstream" and "tar". Both seem to be older Versions instead of the updated once!

High Arbitrary File Overwrite

Package fstream

Patched in >=1.0.12

Dependency of open-color

Path open-color > npm > libcipm > npm-lifecycle > node-gyp > fstream

More info https://nodesecurity.io/advisories/886


High Arbitrary File Overwrite

Package tar

Patched in >=2.2.2 <3.0.0 || >=4.4.2

Dependency of open-color

Path open-color > npm > npm-lifecycle > node-gyp > tar

More info https://nodesecurity.io/advisories/803

Greetings, Subway