Open source maintainer pulls the plug on npm packages colors and faker, now what?
CYBERSECURITY FEATURED ANALYSIS

Open source maintainer pulls the plug on npm packages colors and faker, now what?

SOURCE

Blog RSS Feed | Snyk

DATE

READ

1 min read

Snyk issued a Denial of Service security vulnerability for colors@1.4.1, following this vulnerable code. We highly recommend you revert to colors@1.4.0, and pin your dependencies’ versions to avoid blind upgrades of the …

Snyk issued a Denial of Service security vulnerability for colors@1.4.1, following this vulnerable code. We highly recommend you revert to colors@1.4.0, and pin your dependencies’ versions to avoid blind upgrades of the offending version. We also recommend you migrate to a different package.