Override glob-parent to 6.0.2 #45
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
glob-parent 5.1.2 is a dev dependency with a CVE https://nvd.nist.gov/vuln/detail/cve-2021-35065
This sets an override so glob-parent will always be 6.0.2+, even if the nested dependency asks for 5.1.2.
Motivation and Context
To keep dependencies up-to-date and free of CVEs
How Has This Been Tested?
Installing in clean directory, I confirmed only the glob-parent 6.0.2 version was installed in node_modules. I also confirmed the unit tests and example app still work.
Types of Changes