Fix `eslint-config-stripes` security vulnerability reported in minimist < 1.2.2

Description

Remediation

Upgrade minimist to version 1.2.2 or later. For example:

Always verify the validity and compatibility of suggestions with your codebase.

Details

GHSA-7fhm-mqm4-2wp7

moderate severity

*Vulnerable versions:* < 1.2.2

*Patched version:* 1.2.2

There are high severity security vulnerabilities in two of ESLints dependencies:

The releases 1.8.3 and lower of svjsl (JSLib-npm) are vulnerable, but only if installed in a developer environment. A patch has been released (v1.8.4) which fixes these vulnerabilities.

Identifiers:

  • CVE-2020-7598

  • SNYK-JS-ACORN-559469 (does not have a CVE identifier)

Environment

None

Potential Workaround

None

relates to

Checklist

hide

TestRail: Results

Activity

Show:

Ryan Berger June 26, 2020 at 5:19 PM

Merged resolution into `platform-core` and `platform-complete` snapshot branches.

Khalilah Gambrell March 25, 2020 at 4:01 PM

- will do.

Peter Murray March 25, 2020 at 3:42 PM

: Could you work this into Stripes Force sprint planning, please?

Done

Details

Assignee

Reporter

Priority

Sprint

Development Team

Stripes Force

TestRail: Cases

Open TestRail: Cases

TestRail: Runs

Open TestRail: Runs
Created March 24, 2020 at 3:55 PM
Updated October 19, 2020 at 4:26 PM
Resolved June 26, 2020 at 5:19 PM
TestRail: Cases
TestRail: Runs