klei/gulp-inject

Security Issue: event-stream package is compromised

rand0me opened this issue · 3 comments

As mentioned in this issue event-stream package >= 3.3.6 is not trusted and should be downgraded to 3.3.4

rejas commented

isnt 4.0.1 also acceptable? running npm ls flatmap-stream comes up empty

rejas commented

pinned in v5.0.2

Yeah, 4.0.1 version isn't affected, but some comments says:

but any future version can't be trusted

I'm just reporting the fact, so anyone can decide should it been upgraded or not