-
Notifications
You must be signed in to change notification settings - Fork 72
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Dependency mongodb-extended-json is no longer maintained and has known vulnerabilities. #50
Comments
Thanks for flagging! Happy to field a pull request if you've got the time. |
I have some time but I may not have the ability given I have never contributed to a package before (but now would be a good time to start considering I use this package in my project). Seems to me that the offending package is used once in
If I'm not mistaken the only thing that needs to be done is to:
If what I've written is correct, I'm happy to make those changes. |
This project depends on
"mongodb-extended-json": "^1.7.1"
. According to the readme it's no longer maintained and recommends mongodb-extjson.mongodb-extended-json also depends on the event-stream library recently affected by malware: dominictarr/event-stream#116.
The text was updated successfully, but these errors were encountered: