Any plans to upgrade vulnerable dependencies?
Opened this issue · 0 comments
nexjhealth commented
Hi there,
Do you have any plan to merge the following PRs in a near future: #162, #160, #157 and #156
The adbkit dependency shold also be changed to use @devicefarmer/adbkit since OpenSTF no longer maintains this project (openstf/adbkit#132). And bumping adbkit to @devicefarmer/adbkit 3.2.3 would also fix a bunch of node-forge vulnerabilities (GHSA-x4jg-mjrx-434g, GHSA-cfm4-qjh2-4765, GHSA-92xj-mqp7-vmcj, GHSA-2r2c-g63r-vccr, GHSA-8fr3-hfg3-gpgp, GHSA-5rrq-pxf6-6jx5, GHSA-wxgw-qj99-44c2 and GHSA-gf8q-jrpm-jvxq).
Or maybe monaca-lib isn't affected by these vulnerabilities?
Thank you