Skip to content

Conversation

@Vages
Copy link

@Vages Vages commented Sep 27, 2021

Upgrade dependency cpy-cli to latest version to remove vulnerabilities in transitive dependencies, most importantly in trim-newlines,

Results of running yarn audit --groups dependencies --no-lockfile (install dependencies as if your pakage depended on it and all versions resolved to the newest available):
Before upgrading: Severity: 8 Low | 8 Moderate | 7 High
After upgrading: Severity: 10 Low | 6 Moderate | 5 High

I also tried upgrading opn-cli, but that required code changes. I may do it in a separate PR if I find the time.

Warning: cpy-cli>=3 requires node.js 8. This may be a breaking change; I was unfortunately not able to find the currently required version.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant