Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Addressing vulnerability caused by express-device@0.3.13 (#29)
### [Prototype Override Protection Bypass](https://snyk.io/vuln/npm:qs:20170213 Vulnerable module: qs Introduced through: express-device@0.3.13 **Detailed paths:** * Introduced through: spur-web@1.0.0 › express-device@0.3.13 › express@3.21.2 › connect@2.30.2 › qs@4.0.0 * Introduced through: spur-web@1.0.0 › express-device@0.3.13 › express@3.21.2 › connect@2.30.2 › body-parser@1.13.3 › qs@4.0.0 ### [Regular Expression Denial of Service (DoS)](https://snyk.io/vuln/npm:negotiator:20160616) Vulnerable module: negotiator Introduced through: express-device@0.3.13 **Detailed paths:** * Introduced through: spur-web@1.0.0 › express-device@0.3.13 › express@3.21.2 › connect@2.30.2 › compression@1.5.2 › accepts@1.2.13 › negotiator@0.5.3 * Introduced through: spur-web@1.0.0 › express-device@0.3.13 › express@3.21.2 › connect@2.30.2 › serve-index@1.7.3 › accepts@1.2.13 › negotiator@0.5.3 --- Also correcting the package version.
- Loading branch information