-
-
Notifications
You must be signed in to change notification settings - Fork 11
Open
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency filegood first issueGood for newcomersGood for newcomers
Description
Can a new version be released in order to address this security vulnerability?
Dependabot cannot update set-value to a non-vulnerable version
The latest possible version that can be installed is 2.0.1 because of the following conflicting dependencies:
@codedoc/[email protected] requires set-value@^2.0.0 via a transitive dependency on [email protected]
@codedoc/[email protected] requires set-value@^2.0.1 via a transitive dependency on [email protected]
The earliest fixed version is 4.0.1.
loreanvictor
Metadata
Metadata
Assignees
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency filegood first issueGood for newcomersGood for newcomers