Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

serverless-sam is depending on a version of npm with multiple vulnerable dependencies #33

Open
sonya opened this issue Jan 11, 2019 · 0 comments

Comments

@sonya
Copy link

sonya commented Jan 11, 2019

The latest version of serverless-sam includes "npm": "^5.7.1" as a direct dependency.

Adding serverless-sam to an existing Node project using npm install serverless-sam immediately results in 14 reports of security vulnerabilities from underlying dependencies. All 14 vulnerabilities can be traced to dependencies of the npm package.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant