You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@qpid.apache.org by "Ernest Allen (Jira)" <ji...@apache.org> on 2020/08/04 14:53:00 UTC

[jira] [Created] (DISPATCH-1741) Update console dependency for yargs-parser to avoid security warning

Ernest Allen created DISPATCH-1741:
--------------------------------------

             Summary: Update console dependency for yargs-parser to avoid security warning
                 Key: DISPATCH-1741
                 URL: https://issues.apache.org/jira/browse/DISPATCH-1741
             Project: Qpid Dispatch
          Issue Type: Bug
          Components: Console
    Affects Versions: 1.13.0
            Reporter: Ernest Allen
            Assignee: Ernest Allen


A new security vulnerability was identified with the released version of yargs-parser.
The dependency path is
react-scripts > webpack-dev-server > yargs > yargs-parser

Since react-scripts has not been updated to require the version of yargs-parser that fixes the vulnerability, the package-lock.json file needs to be updated manually to require yargs-parser version 13.1.2

See https://github.com/facebook/create-react-app/issues/9033 for a discussion on the issue with react-scripts.






--
This message was sent by Atlassian Jira
(v8.3.4#803005)

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@qpid.apache.org
For additional commands, e-mail: dev-help@qpid.apache.org