Replies: 1 comment
-
package-lock is not published to npm, your install will not use 2.13.4 just because it's in this repo's package-lock in a historical commit.
There's no need for any of this, a fresh install or npm upgrade always uses the latest semver matching version. I.e. ^2.13.4 which resolves to |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Context
Proposal
I propose to create another backwards-maintained version - 7.14.4 - which only updates koa to the non-vulnerable version 2.15.14, or even version 2.16.2 (which is the latest 2.x version).
From my testing, such update of dependency works smoothly, with no other changes.
If the maintainers agree, I have a PR ready to submit.
Would love to hear what you think.
Thanks!
Beta Was this translation helpful? Give feedback.
All reactions