zkat / npx

execute npm package binaries (moved)

Home Page:https://github.com/npm/npx

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Medium severity vuln found in mem@1.1.0, introduced via yargs@11.1.0

trollepierre opened this issue · comments

✗ Medium severity vuln found in mem@1.1.0, introduced via libnpx@10.2.0
Description: Denial of Service (DoS)
Info: https://snyk.io/vuln/npm:mem:20180117
From: libnpx@10.2.0 > yargs@11.1.0 > os-locale@2.1.0 > mem@1.1.0

+1 for this!

Any chance of seeing an update to use yars@^12.0.2 (to get to os-locale 3 and then to mem 3)?