yargs-parser vulnerability
envgap__webpack__webpack-dev-server-2559
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
375ab2332706ead66335e8f54391ef37f718e129- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
webpack/webpack-dev-server #2559 · read the original issue
- Node Version: 12.16.1 - NPM Version: 6.13.4 - OS: Ubuntu 19.10 - [x] This is a **bug** - [ ] This is a **modification** request Hey guys, npm is reporting a Prototype Pollution vulnerability on the yargs-parser dependency Low Prototype Pollution Package yargs-parser Patched in >=13.1.2 <14.0.0 || >=15.0.1 <16.0.0 || >=18.1.2 Dependency of webpack-dev-server [dev] Path webpack-dev-server > yargs > yargs-parser More info https://npmjs.com/advisories/1500
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]