Skip to content
This repository has been archived by the owner on Sep 2, 2022. It is now read-only.

Upgrade npm-run #4373

Closed
wants to merge 1 commit into from
Closed

Upgrade npm-run #4373

wants to merge 1 commit into from

Conversation

tianhuil
Copy link

Avoid a vulnerability in older version of npm-run's [email protected]: https://nvd.nist.gov/vuln/detail/CVE-2017-16024

Avoid a vulnerability in older version of `npm-run`'s `[email protected]`: https://nvd.nist.gov/vuln/detail/CVE-2017-16024
@CLAassistant
Copy link

CLAassistant commented Apr 13, 2019

CLA assistant check
All committers have signed the CLA.

@pantharshit00
Copy link
Contributor

pantharshit00 commented Apr 16, 2019

Hi @tianhuil

As discussed in prisma/prisma#3723 (comment) upgrading it to v5 will break windows support. RIght now we are waiting for for timoxley/npm-run#21. But this vulnerability only occurs in development so I think we are safe waiting rather than breaking windows build.

We are already planning for the next iteration of our CLI for prisma 2 and in that, we will avoid using this altogether.

@janpio janpio closed this Sep 1, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants