Skip to content

fix(deps): bump meow from 3.x.x to 9.x.x [security] CVE-2021-33623#6

Merged
kevva merged 1 commit intokevva:masterfrom
wejendorp:bump
Jul 2, 2021
Merged

fix(deps): bump meow from 3.x.x to 9.x.x [security] CVE-2021-33623#6
kevva merged 1 commit intokevva:masterfrom
wejendorp:bump

Conversation

@wejendorp
Copy link
Contributor

@wejendorp wejendorp commented Jun 10, 2021

This should fix GHSA-7p7h-4mm5-852v vulnerabilities downstream in any pkgs that use this.

Bump to meow@9 (and not 10) due to ESM compat. Fix to avoid using meow@3.7.0 which pulls trim-newlines@1.0.0.

Tested locally with example from README, the cli works fine without any breaking changes.

@wejendorp wejendorp changed the title fix(deps): bump meow from 3.x.x to 9.x.x [security] fix(deps): bump meow from 3.x.x to 9.x.x [security] CVE-2021-33623 Jun 10, 2021
@Pierstoval
Copy link

Tested locally too, works like a charm.

Friendly ping @kevva, what do you need to go further on this subject? 😉

@kevva kevva merged commit 1c17d5c into kevva:master Jul 2, 2021
@kevva
Copy link
Owner

kevva commented Jul 2, 2021

Thanks! Will publish a new release tomorrow.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants