-
Notifications
You must be signed in to change notification settings - Fork 676
Open
Description
Describe the bug
Currently, @lhci/cli
0.14.0 has a number of vulnerabilities
Here is one we identified:
https://security.snyk.io/vuln/SNYK-JS-COOKIE-8163060
Issues with no direct upgrade or patch:
✗ Cross-site Scripting (XSS) [Medium Severity][https://security.snyk.io/vuln/SNYK-JS-COOKIE-8163060] in cookie@0.4.2
introduced by @lhci/cli@0.14.0 > express@4.20.0 > cookie@0.6.0 and 7 other path(s)
This issue was fixed in versions: 0.7.0
ejclark, KadenThomp36, timbru31, lukemaslany-next and rostoml
Metadata
Metadata
Assignees
Labels
No labels