dominictarr/rc

INI version used (1.3.0) has a vulnerability

aliasdhacker opened this issue · 4 comments

INI dependency needs to be upgraded. CircleCI does not like this version of INI because it has a vulnerability.

https://www.npmjs.com/advisories/1589

INI needs to be 1.3.6 or later -

There is a pull request ready for this: #121

switch to run-con

The ini version is defined as ~1.3.0 which is equivalent to 1.3.x, so there should actually be no need for an update of rc, right?

yeah i guess people could just update to 1.3.6, which is unaffected