-
Notifications
You must be signed in to change notification settings - Fork 934
@commitlint/parse using outdated version of conventional-changelog-angular #2032
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
It's already merged. Next |
Please give this a try: |
@escapedcat thank you. I'm updating right now. |
The issue persists, @commitlint/parse is still declaring conventional-changelog-angular "^5.0.0" in its package.json: commitlint/@commitlint/parse/package.json Line 41 in cb1028e
|
@glumia because of the |
Aaa you are right sorry! There must be some problem with yarn because I solved the issue just removing by hand a line in the lock file* 😅 Thanks! *I was somehow ending up with two lines for conventional-changelog-angular@^5.x.x in the yarn.lock file, one was causing the install of version 5.0.11 and the other one of version 5.0.10 (that brought the vulnerability issue). |
v11.0.0 has been released as |
dot-prop dependency security issue was addressed as part of PR at conventional-changelog/conventional-changelog#647
Affected packages
Possible Solution
update package.json
Context
Allows for prototype pollution: GHSA-ff7x-qrg7-qggm
The text was updated successfully, but these errors were encountered: