Skip to content

Conversation

@MannyPamintuanWorkAccount
Copy link
Contributor

A Security Vuln was identified in the Colors package for >1.4.0, offending packages being 1.4.1, 1.4.44-liberty

This PR pins the color package to 1.4.0 as advised on the snyk page

A Security Vuln was identified in the Colors package for >1.4.0, offending packages being `1.4.1`, `1.4.44-liberty`

This PR pins the color package to `1.4.0`
@DABH
Copy link
Contributor

DABH commented Jan 9, 2022

Shoot, I thought we had pinned this already. Thank you.

@DABH DABH merged commit 05bda20 into winstonjs:master Jan 9, 2022
@MannyPamintuanWorkAccount
Copy link
Contributor Author

Shoot, I thought we had pinned this already. Thank you.

You're most welcome David (@DABH)! I appreciate the speed of review and approval!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants