-
Notifications
You must be signed in to change notification settings - Fork 80
Open
Description
The current release of gulp-istanbul (1.1.1) (transitively) requires [email protected] which is deprecated. The warning we get on an npm install has management worried:
npm WARN deprecated [email protected]:
Please update to minimatch 3.0.2 or higher to avoid a RegExp DoS issue
The dependency chain to minimatch is:
As far as I can see upgrading to a newer istanbul-threshold-checker would be sufficient to get [email protected]. It looks like this is already done in package.json in master. Would it be possible to release a new version of gulp-istanbul so the latest version no longer installs deprecated dependencies?
Metadata
Metadata
Assignees
Labels
No labels