Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependency vulnerabilities cached-path-relative, shell-quote #2032

Open
sulthan-ahmed opened this issue Mar 9, 2022 · 1 comment
Open

Dependency vulnerabilities cached-path-relative, shell-quote #2032

sulthan-ahmed opened this issue Mar 9, 2022 · 1 comment

Comments

@sulthan-ahmed
Copy link

Hi are there plans to continue to update browserify with the latest security patches to dependencies?

Snyk is complaining about vulnerabilities in the following dependencies:

  • cached-path-relative from 1.0.2
  • shell-quote@1.7.2
@sulthan-ahmed sulthan-ahmed changed the title Depedency vulnerabilities cached-path-relative Dependency vulnerabilities cached-path-relative, shell-quote Mar 9, 2022
@ljharb
Copy link
Member

ljharb commented Mar 9, 2022

If they’re in-range, an update is unnecessary because semver allows you to update them in your own application.

If they’re not in-range, it would depend on the breaking changes between the current version we’re on and the one you want us to update to.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

2 participants