Skip to content

Conversation

@loChris
Copy link

@loChris loChris commented Sep 17, 2021

Updating set-value version from 3.0.0 to 4.1.0 since the v3 has a security vulnerability.

CVE-2021-23440

@abdulgit2021
Copy link

@jonschlinkert, @doowb can you please review and merge this PR. it helps in resolving vulnerability

@jonschlinkert
Copy link
Owner

Apologies, I'm trying to spend more time on open source lately, I'll do this ASAP.

@nmccready
Copy link

@jonschlinkert any ETA?

@jonschlinkert
Copy link
Owner

jonschlinkert commented Oct 8, 2021 via email

@martinmckenna
Copy link

still need this @jonschlinkert. There's quite a bit of packages that use this and subsequently also have security vulnerabilities

@shanbady
Copy link

shanbady commented Nov 9, 2021

@jonschlinkert any update on this? We are also waiting on this upstream change.

@matrunchyk
Copy link

Just a humble reminder on this issue

@matrunchyk
Copy link

One more reminder, please @jonschlinkert :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants