Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Lite-server dependecies are vulnerable (The Async package have a vulnerability) #207

Open
DavidUpegui opened this issue May 3, 2022 · 0 comments

Comments

@DavidUpegui
Copy link

Lite-server dependecies are vulnerable (The Async package have a vulnerability)

When I install lite-server with de command npm install Lite-server appear that there are 4 high vulnerabilities.

First of all, I'm new with this technology so I can be wrong or something like that. By the way, the 4 High vulnerabilities come from a
vulnerable version of the Async package (This vulnerability was fixed in the cersion 2.6.4 and lite-server install the version 1.5.x). I actually don't know how to update Async (since is a nested dependency) but I think that is possible to change the predetermined version for installing and save money for the people who install lite-server (well, I don't know if it's possible but I think that it is).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant