Skip to content
This repository was archived by the owner on Oct 26, 2020. It is now read-only.

Conversation

@PieterGit
Copy link
Contributor

@PieterGit PieterGit commented Mar 20, 2019

see https://npmjs.com/advisories/782

After integration of minimed-connect-to-nightscout into Nightscout. I get the following npm security warning:

$ npm audit
                       === npm audit security report ===
# Run  npm update lodash --depth 2  to resolve 1 vulnerability
  Moderate        Prototype Pollution
  Package         lodash
  Dependency of   minimed-connect-to-nightscout
  Path            minimed-connect-to-nightscout > lodash
  More info       https://npmjs.com/advisories/782

Since Nightscout 0.11 the Nightscout release policy is not to release versions with known security issues.
As I'm not a minimed-connect-to-nightscout user, I can't test this. I'm just providing the PR for the community sake.

@mddub Can you please review, test and merge this PR and release a new version.

@PieterGit
Copy link
Contributor Author

Note that this PR also does a major update of the mocha package.
I only tested that this PR still passes all its tests, but didn't do any code changes for mocha.

@mddub
Copy link
Owner

mddub commented Mar 24, 2019

lgtm if tests pass.

@mddub mddub merged commit 00648cc into mddub:master Mar 24, 2019
@mddub
Copy link
Owner

mddub commented Mar 24, 2019

Just updated to v1.2.2 in 83f8d46 and published to npm (I made a mistake in publishing v1.2.1, so skip that one).

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants