Bcrypt 'ini' v1.3.5 dependency is vulnerable
envgap__kelektiv__node.bcrypt.js-850
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
7c5d8df929280b0c7e55cd82f9c03452fae50ccf- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
kelektiv/node.bcrypt.js #850 · read the original issue
Hi, Please update your 'ini' dependency to 1.3.6, 1.3.5 has this vulnerability: 
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]