Skip to content

High vulnerability found for node-forge@0.9.0 (Need to upgrade to 0.10.0) #2755

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
1 task
phoebe-rival opened this issue Oct 1, 2020 · 2 comments
Closed
1 task

Comments

@phoebe-rival
Copy link

phoebe-rival commented Oct 1, 2020

  • Operating System: N/A
  • Node Version: All
  • NPM Version: All
  • webpack Version: N/A
  • webpack-dev-server Version: 3.11.0
  • Browser: N/A
  • [X ] This is a bug
  • This is a modification request

Code

npm-audit-ci-wrapper --threshold=high 

returns:

node-forge@0.9.0  high      https://www.npmjs.com/advisories/1561

Expected Behavior

Upgrade and remove this vulnerability

Actual Behavior

For Bugs; How can we reproduce the behavior?

For Features; What is the motivation and/or use-case for the feature?

@piraces
Copy link

piraces commented Oct 2, 2020

There are two PRs related to this... Hope they merge them soon.
For reference:
#2752
#2740

@alexander-akait
Copy link
Member

Please update your lock file, we use ^ to avoid extra releasing when something broken in transitive deps

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants