Bug#954835: buster-pu: package node-yargs-parser/11.1.1-1+deb10u1

2020-03-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Tue, 2020-03-24 at 11:00 +0100, Xavier Guimard wrote: > node-yargs-parser is vulnerable to prototype pollution. I fixed it > and added a basic test taken from [1]. > +node-yargs-parser (11.1.1-1+deb10u1) unstable; urgency=medium You want "buster" there, not "unst

Bug#954835: buster-pu: package node-yargs-parser/11.1.1-1+deb10u1

2020-03-24 Thread Xavier Guimard
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu Hi, node-yargs-parser is vulnerable to prototype pollution. I fixed it and added a basic test taken from [1]. Sid version is fixed (18.1.1-1). Cheers, Xavier [1] https://snyk.io/