Commit bfda0d0
committed
feat: add multi-path-same-vuln regression fixture (#528)
Craft a minimal express lockfile where qs@6.15.1 and qs@6.14.2 share the
same advisory but need different fix commands — npm update qs for the
body-parser within-range path and npm install express@4.22.2 for the
direct express parent upgrade.1 parent d712033 commit bfda0d0
4 files changed
Lines changed: 993 additions & 0 deletions
File tree
- examples
- multi-path-same-vuln
- tests
0 commit comments