Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

security: patch request for CVE-2023-28155 #18208

Merged
merged 2 commits into from
Mar 17, 2023

Conversation

legobeat
Copy link
Contributor

@legobeat legobeat commented Mar 17, 2023

GHSA-p8p7-x288-28g6

Ported from request/request#3444

This is notably used by web3-provider-engine and the reason CI deps audits in develop is currently failing: https://app.circleci.com/pipelines/github/MetaMask/metamask-extension/39790/workflows/8a74f244-ffc4-4323-b909-95c5e403885d/jobs/1096152

@github-actions
Copy link
Contributor

CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes.

@legobeat legobeat requested a review from kumavis March 17, 2023 00:15
@legobeat legobeat marked this pull request as ready for review March 17, 2023 00:19
@legobeat legobeat requested a review from a team as a code owner March 17, 2023 00:19
@legobeat legobeat requested a review from adonesky1 March 17, 2023 00:19
@codecov
Copy link

codecov bot commented Mar 17, 2023

Codecov Report

Merging #18208 (54366cc) into develop (d45c4ed) will decrease coverage by 0.01%.
The diff coverage is n/a.

@@             Coverage Diff             @@
##           develop   #18208      +/-   ##
===========================================
- Coverage    64.05%   64.04%   -0.01%     
===========================================
  Files          913      913              
  Lines        35568    35568              
  Branches      9014     9014              
===========================================
- Hits         22781    22779       -2     
- Misses       12787    12789       +2     

see 2 files with indirect coverage changes

Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here.

@Wallyworldg02

This comment was marked as off-topic.

Copy link
Member

@Gudahtt Gudahtt left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@Gudahtt Gudahtt merged commit c21c2bd into MetaMask:develop Mar 17, 2023
@github-actions github-actions bot locked and limited conversation to collaborators Mar 17, 2023
@legobeat legobeat deleted the patch-request-ssrf branch March 21, 2023 05:43
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants