-
Notifications
You must be signed in to change notification settings - Fork 41
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[project] Unused npm-watch dependency #200
Comments
Depends too on |
Just wanted to give support to this issue, as |
|
GitLab detects this as high severity risk!
I really think you should upgrade or remove that package. If this isn't done after one year (even when receiving PRs, the project seems abandoned, which would be a sad for the whole Ionic community. To still be compliant we overrule the dependency in the
|
Seems like this can be closed as de23267 fixed it so version 7.1.0 and up are not vulnerable anymore. |
this has been fixed when removing npm-watch in ticket #224 and version 7.1.3 |
The
@trapezedev/project
depends onnpm-watch
but it seems not to be used anywhere.npm-watch
seems not to be regularly mantained.npm-watch
depends onnodemon@^2.0.7
(06/01/2021).Right now nodemon is 3.0.1.
On an
npm audit fix
it raises aSeverity: moderate
Maybe this dependency could be removed if not used anywhere.
The text was updated successfully, but these errors were encountered: