Skip to content

Security: Update got package to fix UNIX socket redirect vulnerability (CVE-2022-33987) #15

@jmaddington

Description

@jmaddington

Description

The got package has a medium severity vulnerability (CVE-2022-33987) that could allow a redirect to a UNIX socket.

Details

Proposed Solution

Add an override/resolution for got to ensure version 11.8.5 or higher is used throughout the dependency tree:

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions