Skip to content

xml2js pin is to a version with a security vulnearbility #14

@Julian

Description

@Julian

Describe the bug
The pinned version of xml2js is vulnerable to this vulnerability which dependabot will flag.

To Reproduce
Steps to reproduce the behavior:

  1. Install podcast-feed-parser
  2. Enable dependabot

Expected behavior
Upgrade to >0.5.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions