Skip to content

Use yargs-parser@18.1.2 - #231

Merged
whymarrh merged 1 commit into
MetaMask:developfrom
whymarrh:update-yargs-parser
May 7, 2020
Merged

Use yargs-parser@18.1.2#231
whymarrh merged 1 commit into
MetaMask:developfrom
whymarrh:update-yargs-parser

Conversation

@whymarrh

Copy link
Copy Markdown
Contributor

This PR updates yargs-parser in our dependency tree to address 25 security advisories of the form shown below. See also: https://www.npmjs.com/advisories/1500.

┌───────────────┬──────────────────────────────────────────────────────────────┐
│ low │ Prototype Pollution │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ yargs-parser │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=13.1.2 <14.0.0 || >=15.0.1 <16.0.0 || >=18.1.2 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ jest │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ jest > @jest/core > jest-runtime > yargs > yargs-parser │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://www.npmjs.com/advisories/1500 │
└───────────────┴──────────────────────────────────────────────────────────────┘

@whymarrh
whymarrh requested review from Gudahtt and rekmarksMay 7, 2020 19:34

@GudahttGudahtt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@rekmarksrekmarks left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@whymarrh
whymarrh merged commit dfe8808 into MetaMask:developMay 7, 2020
@whymarrh
whymarrh deleted the update-yargs-parser branch May 7, 2020 19:38
Mrtenz pushed a commit that referenced this pull request Oct 16, 2025
Mrtenz pushed a commit to Mrtenz/core that referenced this pull request Jun 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@whymarrh@Gudahtt@rekmarks