Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Requesting to upgrade few internal dependent packages which seems to have potential fixes reported in OSS CVE #161

Open
mannerni opened this issue Jul 12, 2021 · 0 comments

Comments

@mannerni
Copy link

Request to upgrade & known timeline for the same would help.

  1. cookie: upgrade to 0.4.1 (Has Fix maxAge option to reject invalid values. Link: https://github.com/jshttp/cookie/releases/tag/v0.4.1.)
  2. util: upgrade to 0.12.4.
  3. string_decoder: upgrade to 1.3.0
  4. readable-stream: upgrade to 3.6.0
    Also would like to understand the impact when users do not use such code (above ones) directly, is it safe to say that internally also these package code is not used untill then?
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant