Skip to content

Conversation

nikolas
Copy link

@nikolas nikolas commented Jan 24, 2024

Previous versions of simple-get are vulnerable to CVE-2022-0355.

https://nvd.nist.gov/vuln/detail/CVE-2022-0355

Thanks for contributing!

  • Have you updated CHANGELOG.md?

@LinusU
Copy link
Collaborator

LinusU commented Jan 25, 2024

Our usage of simple-get is not vulnerable. We cannot upgrade without a breaking change, so this will be fixed in the next major.

More info: #2223 (comment)

@LinusU LinusU closed this Jan 25, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants