Uploaded image for project: 'Thrift'
  1. Thrift
  2. THRIFT-4757

grunt-shell-spawn drags in sync-exec which has a security notice

    XMLWordPrintableJSON

Details

    Description

      root@efc557466b90:/thrift/src/lib/js# npm audit
      
                             === npm audit security report ===
      
      
                                       Manual Review
                   Some vulnerabilities require your attention to resolve
      
                Visit https://go.npm.me/audit-guide for additional guidance
      
      
        Moderate        Tmp files readable by other users
      
        Package         sync-exec
      
        Patched in      No patch available
      
        Dependency of   grunt-shell-spawn [dev]
      
        Path            grunt-shell-spawn > sync-exec
      
        More info       https://nodesecurity.io/advisories/310
      
      found 1 moderate severity vulnerability in 2788 scanned packages
        1 vulnerability requires manual review. See the full report for details.
      

      Attachments

        Activity

          People

            jking3 James E. King III
            jking3 James E. King III
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0h
                0h
                Logged:
                Time Spent - 20m
                20m