Skip to content

Update vulnerable dependencies#2

Open
rthomazel wants to merge 1 commit intotradle:masterfrom
popstand:update/vulnerabilities
Open

Update vulnerable dependencies#2
rthomazel wants to merge 1 commit intotradle:masterfrom
popstand:update/vulnerabilities

Conversation

@rthomazel
Copy link

No description provided.

@mvayngrib
Copy link
Member

why levelup 4.1.0? Is it known to work with level-filesystem 1.2.0?

@rthomazel
Copy link
Author

Working fine for me so far. I just bumped to the latest.

@mvayngrib
Copy link
Member

it would be good to run their test suite to make sure. Their devDependencies show levelup@^0.18.2, see: https://github.com/mafintosh/level-filesystem/blob/master/package.json#L21

@lcsvcn
Copy link

lcsvcn commented Aug 29, 2019

Any update on this? 2 high and 1 moderate security issue

@rthomazel
Copy link
Author

rthomazel commented Aug 29, 2019 via email

@lcsvcn
Copy link

lcsvcn commented Sep 11, 2019

If you need some help let me know @Thomazella

@mvayngrib mvayngrib mentioned this pull request Sep 11, 2019
@rthomazel
Copy link
Author

rthomazel commented Sep 11, 2019 via email

@ripzery
Copy link

ripzery commented Apr 14, 2020

Hello @Thomazella. Any update on this?

@AliMeer
Copy link

AliMeer commented Oct 28, 2020

Hi @Thomazella,

There are a now 2 github dependabot security alerts which are directly related to levelup . One for bl and the other for semver.

It will be great to have this PR tested and merged to address both the security alerts.

@0xSmiley
Copy link

Any update on this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants