mirror of
https://github.com/react/react-native-devtools-frontend.git
synced 2026-10-06 20:11:38 +08:00
This CL updates minimist to 1.2.6 to fix a critical security vulnerability: https://nvd.nist.gov/vuln/detail/CVE-2021-44906 The fix was made by running: `npm run install-deps audit fix --audit-level=critical` Bug: none Change-Id: I51103b525d9969e03000d55af86cebdabc7e0366 Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/3591079 Reviewed-by: Mathias Bynens <mathias@chromium.org> Commit-Queue: Brandon Walderman <brwalder@microsoft.com>
20 lines
530 B
Markdown
20 lines
530 B
Markdown
# Security Policy
|
|
|
|
## Supported Versions
|
|
|
|
We're aiming to only support the latest major version of log4js. Older than that is usually *very* old.
|
|
|
|
| Version | Supported |
|
|
| ------- | ------------------ |
|
|
| 6.x | :white_check_mark: |
|
|
| < 6.0 | :x: |
|
|
|
|
## Reporting a Vulnerability
|
|
|
|
Report vulnerabilities via email to:
|
|
|
|
* Gareth Jones <gareth.nomiddlename@gmail.com>
|
|
* Lam Wei Li <lam_wei_li@hotmail.com>
|
|
|
|
Please put "[log4js:security]" in the subject line. We will aim to respond within a day or two.
|