Skip to content
This repository was archived by the owner on Nov 4, 2025. It is now read-only.

Conversation

@fursich
Copy link

@fursich fursich commented Mar 26, 2019

Hi, this PR is related to the issue #1136

I'd like to suggest to use updated morgan to cope with the know vulnerability.

I also updated .bowerrc following the instruction to point to the latest directory. (please see here for details

Apparently (at least in my forked repository) there are a couple of CI errors with the master branch - something related with angular-highlightjs - but I leave it as it is, since I believe it has little to do with these changes.

As I'm quite new to contribute to this package any advises would be appreciated.
Would be cool if we can use this package without getting warnings from github :)

fursich added 2 commits March 26, 2019 17:19
update legacy .bowerrc to point to new Bower registory
https://gist.github.com/sheerun/c04d856a7a368bad2896ff0c4958cb00
This commit is to update one of the dependent node modules 'morgan'
upto version 1.9.1 so as to catch up with its security fix. see also:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5413
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant