dylang / shortid

Short id generator. Url-friendly. Non-predictable. Cluster-compatible.

Home Page:https://www.npmjs.org/package/shortid

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

shortid references to nanoid of ^2.1.0 version which contains vulnerability

VladimirTrunov opened this issue · comments

Hello everyone,

This library references to nanoid of ^2.1.0 version which contains vulnerability. Could anybody please take a look?

Thanks,
-Vladimir

The package nanoid from 3.0.0 and before 3.1.31 are vulnerable

Nano ID 2.1 is not affected.

Oh, yes, I'm sorry