Skip to content

dependency on insecure abandoned module #47

@ckolderup

Description

@ckolderup

Hi,

This library has a dependency on the module slug, which is currently subject to a node security advisory. Looking at the project's Github repo, it does not appear that the maintainer is still around-- their last activity on the repo was in April of 2015, nearly 3 years ago.

Would it be possible to switch to a different dependency? Here are a couple alternatives based on some preliminary research:

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions