This repository was archived by the owner on Jul 29, 2024. It is now read-only.
This repository was archived by the owner on Jul 29, 2024. It is now read-only.
protractor > optimist > minimist Prototype Pollution #5413
Closed
Description
Bug report
- Node Version:
v13.10.1
- Protractor Version:
5.4.3
- Angular Version:
9.1.0
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Low │ Prototype Pollution │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ minimist │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=0.2.1 <1.0.0 || >=1.2.3 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ protractor [dev] │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ protractor > optimist > minimist │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://npmjs.com/advisories/1179 │
└───────────────┴──────────────────────────────────────────────────────────────┘
optimist is deprecated--maybe update to yargs?
Metadata
Metadata
Assignees
Labels
No labels
Activity
fix: security pototype pollution
fix: security prototype pollution
fix: security prototype pollution
fix: security prototype pollution
colbyhill21 commentedon Apr 9, 2020
The change has been completed by @alan-agius4 although it still hasn't been merged in. Is there any estimate on when these changes will be merged and released?
inpercima commentedon Apr 11, 2020
Is there a way to merge this existing pull request?
fix: security prototype pollution
fix: security prototype pollution
fix: security prototype pollution
fix: security prototype pollution
fix: security prototype pollution
fix: security prototype pollution
4 remaining items