-
Notifications
You must be signed in to change notification settings - Fork 3.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[email protected] #1211
Comments
After the mess, the dependency to |
Thank you for the heads up. I have locked the dependency to |
Hi, I'm new to MEAN stack and can anyone please tell me how to safely remove or update this dependency from package-lock.json using NPM |
@shivam183 here is how I did it : remove your |
The
package-lock.json
includes[email protected]
which includes malicious code: package-lock.json#L1090-L1095.See also: dominictarr/event-stream#116
The
event-stream
package looks unsafe. It's better to find an alternative in my 2 cents.The text was updated successfully, but these errors were encountered: