Skip to content

@commitlint/parse using outdated version of conventional-changelog-angular #2032

Closed
@MikeActually

Description

@MikeActually

dot-prop dependency security issue was addressed as part of PR at conventional-changelog/conventional-changelog#647

Affected packages

  • cli
  • core
  • prompt
  • config-angular

Possible Solution

update package.json

Context

Allows for prototype pollution: GHSA-ff7x-qrg7-qggm

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependenciesPull requests that update a dependency file

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions