Skip to content

Conversation

maclover7
Copy link

Bumps node-gyp from ^3.7.0 to ^3.8.0. Highlights in this release are a fix for the security vulnerability warning in request (ref: npm/cli#20), and also upstreams some gyp patches from nodejs/node.

Since the new node-gyp version only came out today, this should probably bake for a little bit, but wanted to open this up just to start the conversation :)

@maclover7 maclover7 requested a review from a team as a code owner August 9, 2018 01:48
@brody4hire
Copy link

Thanks @maclover7. We should also do npm install --save request@2 (request@^2.8.7) which this package uses directly as well.

@zkat
Copy link
Contributor

zkat commented Aug 13, 2018

f861c2b this patch is already in the upcoming npm release. It will be in npm@latest on Wednesday unless something goes terribly awry.

Thank you for taking the time to do this, and my condolences for your work getting preempted, but I'm also happy that we've got this fixed already. Cheers!

@zkat zkat closed this Aug 13, 2018
@maclover7 maclover7 deleted the jm-node-gyp-380 branch August 14, 2018 03:06
isaacs added a commit that referenced this pull request Aug 5, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants