git-promise@1.0.0 vulnerabilities

Simple wrapper to run any git command and process it's output using promises.

Direct Vulnerabilities

Known vulnerabilities in the git-promise package. This does not include vulnerabilities belonging to this package’s dependencies.

Command Injection

git-promise is a Simple wrapper that allows you to run any git command using a more intuitive syntax.

Affected versions of this package are vulnerable to Command Injection due to an inappropriate fix of a prior vulnerability in this package. Note: Please note that the vulnerability will not be fixed. The README file was updated with a warning regarding this issue.

How to fix Command Injection?

There is no fixed version for git-promise.