Skip to content

Vulnerability in child dependency for yargs #2474

@chillheart

Description

@chillheart
  • Operating System: Windows 10, Linux, macOS

  • Node Version: 12.16.1

  • NPM Version: 6.13.4

  • webpack-dev-server Version: 3.9.0

  • Browser: all

  • This is a bug

  • This is a modification request

Expected Behavior

webpack-dev-server uses [email protected] that has a child dependency (yarg-parser) that contains a known vulnerability. The vulnerability has been patched in and updated in yargs@>13.0.0.0.

For Bugs; How can we reproduce the behavior?

The reproduction steps are available on the vulnerability disclosure.

https://snyk.io/vuln/SNYK-JS-YARGSPARSER-560381

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions