Depends on handlebars v4.0.1 which has a severe security vulnerability
IanKemp opened this issue · 3 comments
IanKemp commented
Please see https://www.npmjs.com/advisories/1164
Cazaimi commented
Also see: https://app.snyk.io/vuln/npm:istanbul
@gotwarlost , any ETA on this?
IanKemp commented
BTW, I'm fully aware that this package is deprecated, but a lot of projects still depend on it, hence why I think a release just to update the dependencies would be justified.
mailmrmanoj commented
+1