Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Outdated version of debug - Snyk #37

Closed
knoxcard opened this issue Nov 1, 2017 · 3 comments
Closed

Outdated version of debug - Snyk #37

knoxcard opened this issue Nov 1, 2017 · 3 comments

Comments

@knoxcard
Copy link
Contributor

knoxcard commented Nov 1, 2017

Need to upgrade to the latest version of debug
https://github.com/visionmedia/debug/releases/

✗ Low severity vulnerability found on debug@2.6.8

  • desc: Regular Expression Denial of Service (ReDoS)
  • info: https://snyk.io/vuln/npm:debug:20170905
  • from: node_services@1.0.0 > npm@5.5.1 > pacote@6.0.2 > make-fetch-happen@2.5.0 > https-proxy-agent@2.1.0 > debug@2.6.8
    Your dependencies are out of date, otherwise you would be using a newer debug than debug@2.6.8.
    Try deleting node_modules, reinstalling and running snyk test again.
    If the problem persists, one of your dependencies may be bundling outdated modules.
@knoxcard
Copy link
Contributor Author

knoxcard commented Nov 6, 2017

Pull requests already submitted :-)

@chilltemp
Copy link

Can this ticket remain open until the update has been released to npm? Or, a comment placed here so that others know when to update their dependencies.

@TooTallNate
Copy link
Owner

2.1.1 has been released.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants