[security] bump `find-node-modules` to `2.1.2`
myovchev opened this issue · comments
Miro Yovchev commented
find-node-modules
depends on merge, which has security issues. Currently find-node-modules
package is set to v2.0
. The issue is resolved at the latest package version 2.1.2
.
Richard May commented
David Welch commented
Addressed in #842