question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

Vulnerability 1012 - Need new release

See original GitHub issue

Hey,

There is currently a security vulnerability in your released package 4.1.0 https://www.npmjs.com/advisories/1012

It is due to the version of braces being used, however it looks like that’s been fixed in master. Will there be a release any time soon?

Issue Analytics

  • State:closed
  • Created 4 years ago
  • Reactions:1
  • Comments:6 (2 by maintainers)

github_iconTop GitHub Comments

3reactions
johnjbartoncommented, Jul 12, 2019

Please don’t open issues about these vulnerabilities. We already get tons of notifications and annoying panels in the UI.

If this is important to you, send a PR to fix it.

1reaction
ionut-tcommented, Jul 12, 2019

Hi, I’m getting 110 high severity vulnerabilities in an Angular project, all related to set-value package. Message below:

High: Prototype Pollution
Package: set-value
Patched in >=3.0.1
Dependency of karma [dev]
Path: karma > chokidar > readdirp > micromatch > snapdragon > base > cache-base > union-value > set-value More info: https://npmjs.com/advisories/1012

Read more comments on GitHub >

github_iconTop Results From Across the Web

CVE-2022-1012 - Red Hat Customer Portal
Why is my security scanner reporting my product as vulnerable to this vulnerability even though my product version is fixed or not affected?...
Read more >
CVE-2022-1012 Detail - NVD
CWE-401, Missing Release of Memory after Effective Lifetime, cwe source acceptance level NIST Provider acceptance level Red Hat, Inc.
Read more >
Red Hat: CVE-2022-1012: Important: kpatch-patch security ...
With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what...
Read more >
CVE-2021-1012
The mission of the CVE® Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities.
Read more >
Security Bulletins | Customer Care - Google Cloud
Two new vulnerabilities (CVE-2022-2585 and CVE-2022-2588) have been discovered in the Linux kernel that can lead to a full container break out to...
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found