webpro / dyson

Node server for dynamic, fake JSON.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

dyson dependencies fail npm security audit

bsmithb2 opened this issue · comments

Hi,

dyson 2.0.0 has a fixed dependency on serve-favicon 2.4.3, which has a dependency on fresh 0.5.0.

Fresh versions prior to 0.52.0 have a audit vulnerability as discoverable with npm audit - https://nodesecurity.io/advisories/526

Is it possible to migrate to a version of serve-favicon greater or equal to 2.4.5? This will resolve the vulnerability.

Thanks!

Updated dependencies in v2.0.1

Does the version need updating so it can be released to npm?

No worries @lorilew, I use release-it for this :)