Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerable dependencies found in latest version #922

Open
sakshibatra16 opened this issue Jun 4, 2024 · 0 comments
Open

Vulnerable dependencies found in latest version #922

sakshibatra16 opened this issue Jun 4, 2024 · 0 comments
Labels

Comments

@sakshibatra16
Copy link

Describe the bug
Package is using old versions of child dependencies, which have vulnerability of very high severity.
One of the package is tough-cookie whose version used is V3.0.1 which is vulnerable , and Its minimum version that needs to be upgraded is to V4.1.3

To Reproduce
Steps to reproduce the behavior:

  1. Install the npm package
  2. Observe the package-lock.json file with the child dependencies.
  3. Getting vulnerable versions of child dependencies.

Expected behavior
Latest or package with no vulnerability should be used.

Screenshots

Vulnerability

Additional context
We are using this package from long time, due to this vulnerability in this package we have to remove this package and find an alternative, if this issue is not fixed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant