Skip to content
This repository has been archived by the owner on Jul 24, 2024. It is now read-only.

updated package.json to update node-gyp to 4.0.0 #2661

Closed
wants to merge 1 commit into from

Conversation

ali254
Copy link

@ali254 ali254 commented May 2, 2019

update dependency version of node-gyp to 4.0.0.

In the current version of node-gyp (v3.8.0), it uses "tar": "^2.0.0" which is prone to a vulnerability. See link: https://www.npmjs.com/advisories/803

node-gyp 4.0.0 uses a newer version of tar in which this vulnerability has been fixed.

update dependency version of node-gyp to 4.0.0.

In the current version of node-gyp (v3.8.0), it uses "tar": "^2.0.0" which is prone to a vulnerability. See link: https://www.npmjs.com/advisories/803

node-gyp 4.0.0 uses a newer version of tar in which this vulnerability has been fixed.
@nschonni
Copy link
Contributor

nschonni commented May 2, 2019

This is a duplicate of a bunch of closed PRs as explained in #2625. This won't be merged, but I'll leave it open to see if it prevents other PRs from being opened

@nschonni
Copy link
Contributor

nschonni commented May 2, 2019

Actual #2639 is already the placeholder and hasn't helped prevent people opening the same PR

@nschonni nschonni closed this May 2, 2019
@LaxmiSulakshana
Copy link

This is a duplicate of a bunch of closed PRs as explained in #2625. This won't be merged, but I'll leave it open to see if it prevents other PRs from being opened

Could you please confirm on when it will be fixed. As it is vulnerability issue.

jiongle1 pushed a commit to scantist-ossops-m2/node-sass that referenced this pull request Apr 7, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants