From aa63a01076aac5404a08f8f07f8bd407b41b4efb Mon Sep 17 00:00:00 2001 From: HowWeRollingham Date: Wed, 10 May 2017 13:10:44 +0100 Subject: [PATCH] Update extract-zip version to 1.6.5 extract-zip 1.5.0 depends on concat-steam 1.5.1 which contains a vulnerability https://snyk.io/test/npm/concat-stream/1.5.1 extract-zip 1.6.5 depends an updated version of concat-stream which fixes that vulnerability. https://snyk.io/test/npm/concat-stream/1.6.0 --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index ccd9fadea..b70c8b6ef 100644 --- a/package.json +++ b/package.json @@ -40,7 +40,7 @@ }, "dependencies": { "es6-promise": "~4.0.3", - "extract-zip": "~1.5.0", + "extract-zip": "~1.6.5", "fs-extra": "~1.0.0", "hasha": "~2.2.0", "kew": "~0.7.0",