Skip to content

serverless-sam is depending on a version of npm with multiple vulnerable dependencies #33

@sonya

Description

@sonya

The latest version of serverless-sam includes "npm": "^5.7.1" as a direct dependency.

Adding serverless-sam to an existing Node project using npm install serverless-sam immediately results in 14 reports of security vulnerabilities from underlying dependencies. All 14 vulnerabilities can be traced to dependencies of the npm package.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions