-
-
Couldn't load subscription status.
- Fork 1.5k
Closed
Description
Hi, thanks for the useful plugin!
I noticed the versions of some of this package's dependencies are very old. For example, the read-pkg-up version is from 4 years ago: https://github.com/benmosher/eslint-plugin-import/blob/master/package.json#L114
This can lead to insecure transitive dependencies being brought in for users of this plugin.
For example: eslint-plugin-import > read-pkg-up > read-pkg > normalize-package-data > hosted-git-info@2, which recently had a security alert.
mccraveiro and dpkirchner
Metadata
Metadata
Assignees
Labels
No labels