michaelleeallen / mocha-junit-reporter

A JUnit XML reporter for mocha.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

CVE-2021-44906 Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js

jasonrberk opened this issue · comments

mocha-junit-reporter depends on mkdirp which depends on minimist

which is being flagged by GitHub as CVE-2021-44906