-
Notifications
You must be signed in to change notification settings - Fork 3.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update make-dir
to resolve vulnerable dependency
#3806
Comments
It appears an outdated version of semver is also referenced as a dev dependency here: less.js/packages/less/package.json Line 100 in 4d3189c
|
@iChenLei, is there any update on this? If not, would a pull request be welcome? |
it was fixed on |
That will only fix it if you use This means it would be best if Dunno if this repo is still maintained but I'd be open to creating a pull request. |
@jorenbroekema PR welcome |
the less.js dependency
make-dir
is not up-to-date and causes security warning due to its outdated dependency.see GHSA-c2qf-rxjj-qqgw
I would suggest updating to a current
make-dir
version here.A quick search showed that it is only used here, so from my point of view an update should bring little problems.
less.js/packages/less/bin/lessc
Lines 163 to 172 in 7491578
The text was updated successfully, but these errors were encountered: