Skip to content

Conversation

@btecu
Copy link
Contributor

@btecu btecu commented Oct 12, 2022

Primarily to get rid of the vulnerability caused by mkdirp.

Closes #165.

@btecu
Copy link
Contributor Author

btecu commented Oct 12, 2022

@clayreimann would you be able to get it merged and released?

@btecu
Copy link
Contributor Author

btecu commented Oct 26, 2022

@michaelleeallen would you be able to get it merged and released?

@clayreimann
Copy link
Collaborator

@btecu if the tests pass I'll merge this

@clayreimann
Copy link
Collaborator

@btecu Looks like this is more complicated than a straight upgrade. Do you know if there are stats available for usage of various versions of mocha?

@btecu
Copy link
Contributor Author

btecu commented Oct 26, 2022

@clayreimann would you mind running the tests again?

@clayreimann clayreimann merged commit 2fba24b into michaelleeallen:master Oct 27, 2022
@clayreimann
Copy link
Collaborator

@btecu Released as 2.1.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CVE-2021-44906 Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js

2 participants