Skip to content

Replace open package by opn#132

Open
aslafy-z wants to merge 2 commits into
schickling:masterfrom
aslafy-z:patch-1
Open

Replace open package by opn#132
aslafy-z wants to merge 2 commits into
schickling:masterfrom
aslafy-z:patch-1

Conversation

@aslafy-z
Copy link
Copy Markdown

@aslafy-z aslafy-z commented Oct 2, 2018

Closes #131

┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Critical      │ Command Injection                                            │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ open                                                         │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ No patch available                                           │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ gulp-webserver [dev]                                         │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ gulp-webserver > open                                        │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://nodesecurity.io/advisories/663                       │
└───────────────┴──────────────────────────────────────────────────────────────┘

Open is deprecated: https://github.com/jjrdn/node-open

@aslafy-z
Copy link
Copy Markdown
Author

Travis node versions has to be raised in order to make this build pass.

@ajhartenbaum
Copy link
Copy Markdown

Is this going to be fixed soon?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants