Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependency request uses a vulnerable version of cryptiles #83

Closed
Puzzleton opened this issue Feb 27, 2019 · 2 comments
Closed

Dependency request uses a vulnerable version of cryptiles #83

Puzzleton opened this issue Feb 27, 2019 · 2 comments

Comments

@Puzzleton
Copy link

- jwks-rsa@^1.4.0
  - request@^2.73.0
    - hawk 3.1.3
      - cryptiles 2.x.x

cryptiles has a known high priority vulnerability. The latest version of request (v2.88.0) no longer depends on hawk, thus removing the vulnerability with cryptiles.

@danwkennedy
Copy link

danwkennedy commented Mar 9, 2019

Similarly, it looks like there's a vulnerability in the extend package that [email protected] fixes.

@damieng
Copy link
Contributor

damieng commented May 21, 2019

Fixed in #91 - nothing exists yet for the extend package/beyond 2.88. Might be possible to switch to something other than 'request' in a future version.

@damieng damieng closed this as completed May 21, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants