Bug#941683: buster-pu: package node-yarnpkg/1.13.0-1+deb10u1

2019-11-08 Thread Adam D. Barratt
Control: tags -1 + confirmed On Thu, 2019-10-03 at 20:57 +0200, Xavier Guimard wrote: > node-yarnpkg is vulnerable: it exports auth data in http requests > (#941354, CVE-2019-5448). This patch imports upstream fix. Please go ahead; thanks. Regards, Adam

Bug#941683: buster-pu: package node-yarnpkg/1.13.0-1+deb10u1

2019-10-03 Thread Xavier Guimard
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu Hi, node-yarnpkg is vulnerable: it exports auth data in http requests (#941354, CVE-2019-5448). This patch imports upstream fix. Cheers, Xavier diff --git a/debian/changelog