Old version of csv-parser@1.8.1 has a dependency to "minimist": "^0.2.0" with a prototype pollution vulnerability
enaukkarinen opened this issue · 1 comments
enaukkarinen commented
Could csv-parser dependency be updated to 3.0.0 to get rid of this vulnerability?
Thanks
montumodi commented
@ZJONSSON , @jbreckman - Any thoughts on this?