Skip to content

Test breaking

Low
arguiot published GHSA-mgv2-57vj-99xc Oct 5, 2019 · 1 comment

Package

npm eye.js (NPM)

Affected versions

1.2.0

Patched versions

1.2.1

Description

Impact

In v1.2.0, tests are broken: all tests are always succeeding. If tests are looking for security vulnerabilities, these were compromised.

Patches

Users should upgrade to v1.2.1

Workarounds

Users who don't use eye.js for looking for vulnerabilities are safe. Upgrading will just fix some bugs.

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs