Some vulnerabilities were found for pouchdb-quick-search

50 views
Skip to first unread message

Paweł Psztyć

unread,
Jun 1, 2019, 12:10:20 PM6/1/19
to PouchDB
Hi,

After installing "pouchdb-quick-search" I have 2 security alerts from npm. Both regards "debug" package used in "pouchdb-utils" package. Used version of "debug" is "2.2.0" and should be ">= 2.6.9 < 3.0.0 || >= 3.1.0 ".
I tried to clone the repo and send a PR but I don't know how this monorepo works and how the final package is being build. Is there a way for anyone to fix this issue? Or alt least tell me how to fix it to send a PR?
Thanks
Reply all
Reply to author
Forward
0 new messages