Skip to content

Potential security vulnerability #116

@crishpeen

Description

@crishpeen

We have been reported this issue:

We found a potential security vulnerability in a repository which you have been granted security alert access.

@visionappscz visionappscz/bootstrap-ui
Known moderate severity security vulnerability detected in marked < 0.3.7 defined in package-lock.json.
package-lock.json update suggested: marked ~> 0.3.7.

However marked isn't direct BUI dependency. Its is dependency of https://github.com/kss-node/kss-node/ which is dependency of https://github.com/kss-node/grunt-kss which is finally direct dependency of BUI.

There is already issue in upstream http://github.com/kss-node/kss-node/issues/447

Maybe we should give up on kss, because it causes troubles all the time.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions