Skip to content
This repository was archived by the owner on Nov 4, 2025. It is now read-only.
This repository was archived by the owner on Nov 4, 2025. It is now read-only.

(security alert) morgan needs to be updated #1136

@fursich

Description

@fursich

Hi, first of all thanks really a lot for maintaining the package!

security alert

Just noticed github has been giving an alert for potential vulnerability on morgan, one of its dependencies.

(datailed report here)
https://nvd.nist.gov/vuln/detail/CVE-2019-5413

Understanding that this package has been suffering from low maintainer resources, I thought it would be useful to raise alert as it looks some sort of vulnerability, which (possibly) could be dealt relatively easily by updating the dependencies.

additional info

I'm not very knowledgeable about the internal of this package, but after a quick look-over it looks like the version is locked here, which currently is preventing us from upgrading morgan upto its safe version.
Hope it helps!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions