-
Notifications
You must be signed in to change notification settings - Fork 1.3k
High severity vulnerability detected in yargs #3021
Comments
Thanks, I took a look at the package-lock.json after a fresh install and found that y18n is only a dependency for Also, not seeing anything from |
@nschonni The scanner is still showing y18n as a vulnerability. How did you exclude yargs? I am unable to exclude yargs since node-sass is in my dependencies and node-sass is pulling in yargs. |
I'm still not seeing anything installing locally, you should bring this up with whatever scanning tool vendor you're using |
@nschonni what version of node-sass are you using? Also, what version of node are you using? |
The tool whitesource is actually reporting But I actually do see a direct relation out of
[email protected] vulnerability description: https://snyk.io/test/npm/y18n/4.0.0 Nevertheless it would need to be |
A security assessment was performed and vulnerabilities were found to dependency sane
It is requested to update from version " y18n": "^4.0.0" to " y18n": "^5.0.5"
reference:
yargs/y18n#107
yargs/y18n#108
The text was updated successfully, but these errors were encountered: