In v1.2.0, tests are broken: all tests are always succeeding. If tests are looking for security vulnerabilities, these were compromised.
Users should upgrade to v1.2.1
Users who don't use eye.js for looking for vulnerabilities are safe. Upgrading will just fix some bugs.
If you have any questions or comments about this advisory:
{
"cwe_ids": [],
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:46:09Z",
"nvd_published_at": null,
"severity": "LOW"
}