从GitHub收到警告,超级特工v3.5.2的安全风险很低。超级代理是与square-connect npm一起安装的依赖项。这是手动升级,还是应该单独使用,因为从Square下载了这个API。
Known low severity security vulnerability detected in superagent <3.7.0 defined in package-lock.json.
package-lock.json update suggested: superagent ~> 3.7.0.应用程序运行时具有以下依赖关系:
"square-connect": "^2.20180918.0"https://stackoverflow.com/questions/52789502
复制相似问题