Skip to content

Commit 0e5efdb

Browse files
authored
lock debug to v2.6.9
There is a minor security vulnerability in the module `debug`: https://nodesecurity.io/advisories/534 This was resolved in 2.6.9 and 3.1.0. Debug introduced let/const in v3.2.0, breaking compatibility with node.js v4 and older browsers. This was reverted in 3.2.4, then re-released it in 4.0.0 - see debug-js/debug#603 for context around that. In order avoid the vulnerability without loosing any compatibility, this change locks component-cookie to >= 3.2.4 < 4.0.0. Version `^2.6.9` could alternatively be used if desired. This Fixes #16, Fixes #15, and is is part of the fix for matthewmueller/next-cookies#7
1 parent ec7d208 commit 0e5efdb

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
"version": "1.1.4",
55
"license": "MIT",
66
"dependencies": {
7-
"debug": "2.2.0"
7+
"debug": "^3.2.4"
88
},
99
"devDependencies": {
1010
"mocha": "*"

0 commit comments

Comments
 (0)