-
Notifications
You must be signed in to change notification settings - Fork 55
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix: ⬆️ CVE-2022-0235 #459
Conversation
update node-fetch to 2.6.7 to fix CVE-2022-0235 https://snyk.io/vuln/npm:node-fetch
@chientrm Thank you for your contribution! Could you please update the version number to 2.6.1 in package.json and lib/util/constants.ts? Please also add an entry in the Changelog.md |
@jeremymeng Do we need this update given that semver will ensure the latest version is served? |
@ramya-rao-a I feel it's ok to ensure minimum version to get the security fixes. This sounds a good topic to discuss in our team meeting. |
I updated the version numbers and added an entry in the Changelog. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thank you for the contribution!
@chientrm if a dependency version with security fixes falls into our semver range (in this case |
Had just checked Thank you so much for your response. |
update node-fetch to 2.6.7 to fix CVE-2022-0235