INI version used (1.3.0) has a vulnerability
aliasdhacker opened this issue · 4 comments
aliasdhacker commented
INI dependency needs to be upgraded. CircleCI does not like this version of INI because it has a vulnerability.
https://www.npmjs.com/advisories/1589
INI needs to be 1.3.6 or later -
JimmyBjorklund commented
There is a pull request ready for this: #121
goatandsheep commented
switch to run-con
stieben commented
The ini
version is defined as ~1.3.0
which is equivalent to 1.3.x
, so there should actually be no need for an update of rc
, right?
goatandsheep commented
yeah i guess people could just update to 1.3.6, which is unaffected