Skip to content

Consider updating dependency versions #2144

@jmrossy

Description

@jmrossy

Hi, thanks for the useful plugin!

I noticed the versions of some of this package's dependencies are very old. For example, the read-pkg-up version is from 4 years ago: https://github.com/benmosher/eslint-plugin-import/blob/master/package.json#L114

This can lead to insecure transitive dependencies being brought in for users of this plugin.

For example: eslint-plugin-import > read-pkg-up > read-pkg > normalize-package-data > hosted-git-info@2, which recently had a security alert.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions