The latest version of db-migrate depends on a package with a high severity vulnerability (GHSA-fwr7-v2mv-hh25). It is my understanding that db-migrate does not directly use the affected package async, but rather indirectly imports it via prompt.
Please switch to an unaffected version of prompt or replace it altogether (e.g. #778).
The latest version of
db-migratedepends on a package with ahigh severityvulnerability (GHSA-fwr7-v2mv-hh25). It is my understanding thatdb-migratedoes not directly use the affected packageasync, but rather indirectly imports it viaprompt.Please switch to an unaffected version of
promptor replace it altogether (e.g. #778).