From ec28d881d17d795b19dc2b35a0ef0cf9a6a73a55 Mon Sep 17 00:00:00 2001 From: Nahid Akbar Date: Thu, 13 Jun 2019 15:09:37 +1000 Subject: [PATCH] Update dependency on cryptiles to remedy prototype pollution security vulnerablity in earlier version of library --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 3f181ff..76c14f0 100644 --- a/package.json +++ b/package.json @@ -19,7 +19,7 @@ }, "main": "./lib/passport-wsfed-saml2", "dependencies": { - "cryptiles": "~0.2.2", + "cryptiles": "^4.1.3", "ejs": "2.5.5", "jsonwebtoken": "~5.0.4", "passport-strategy": "^1.0.0",