Skip to content

Update dependency higher-up the tree? #323

@christian-schwaderer

Description

@christian-schwaderer

This is rather a suggestion than an issue.

Today, yarn audit failed warning me about GHSA-78xj-cgh5-2h22 in mongodb>socks>ip

Running npx yarn-audit-fix ended in

Can't find satisfactory version for ip <0.0.0
Upgraded deps: <none>

However, there is actually a solution. Upgrading socks to version 2.7.3 because that package does not contain the vulnerable ip package anymore at all.

I don't know if such things would be too sophisticated, but if yarn-audit-fix could do such things automatically it would make it even better :)

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions