Skip to content

Fix "potential" vulnerability in our dev deps #2584

@etpinard

Description

@etpinard

From https://github.com/plotly/plotly.js/network/dependencies

image

where pkg hoek is the culprit.

From the package-lock file on master on April 27, 2018, we have:

image

where bumping our direct dev-dependencies karma, jsdom and node-sass does not solve the issue. We'll most likely have to wait for request/request#2875 or a similar PR to be merged.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions