This repository has been archived by the owner on Oct 3, 2023. It is now read-only.
This repository has been archived by the owner on Oct 3, 2023. It is now read-only.
Open
Description
Please answer these questions before submitting a bug report.
What version of OpenCensus are you using?
0.0.20
What version of Node are you using?
10.15.1
What did you do?
Run npm install
for my application, then run npm ls minimist
What did you expect to see?
opencensus-node should only depend on packages that do not contain vulnerabilities.
What did you see instead?
Here's the dependency graph:
+-- @opencensus/[email protected]
| -- @opencensus/[email protected] |
-- @opencensus/[email protected]
| -- [email protected] |
-- [email protected]
| +-- [email protected]
| | -- [email protected] |
-- [email protected]
| `-- [email protected]
Additional context
minimist v0.0.8 and minimist v1.2.0 contain a vulnerability - see https://vuln.whitesourcesoftware.com/vulnerability/CVE-2020-7598/