Commit 0e5efdb
authored
lock debug to v2.6.9
There is a minor security vulnerability in the module `debug`: https://nodesecurity.io/advisories/534
This was resolved in 2.6.9 and 3.1.0.
Debug introduced let/const in v3.2.0, breaking compatibility with node.js v4 and older browsers. This was reverted in 3.2.4, then re-released it in 4.0.0 - see debug-js/debug#603 for context around that.
In order avoid the vulnerability without loosing any compatibility, this change locks component-cookie to >= 3.2.4 < 4.0.0.
Version `^2.6.9` could alternatively be used if desired.
This Fixes #16, Fixes #15, and is is part of the fix for matthewmueller/next-cookies#71 parent ec7d208 commit 0e5efdb
1 file changed
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
7 | | - | |
| 7 | + | |
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| |||
0 commit comments