Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix sshpk version #80

Closed
wants to merge 1 commit into from
Closed

Fix sshpk version #80

wants to merge 1 commit into from

Conversation

iwko
Copy link

@iwko iwko commented Oct 18, 2018

This is fix for #79

@k001
Copy link

k001 commented Jan 30, 2019

Any ETA to apply this fix?

@iwko
Copy link
Author

iwko commented Jan 31, 2019

@arekinath

@eran10
Copy link

eran10 commented Feb 13, 2019

Any ETA to apply this fix?

@davidlehn
Copy link
Contributor

"Fix"? This patch locks sshpk to a version released in 2015 just to support Node.js 0.8.28 released in 2014? Seems like you're on your own for an edge case like this.

@ejoubaud
Copy link

ejoubaud commented Jun 5, 2019

👎 to this, sshpk < 1.13.2 has an identified vulnerability: https://hackerone.com/reports/319593 This change would cause any project using this lib even indirectly to get audit failures and vulnerability alerts.

@spanditcaa spanditcaa mentioned this pull request Oct 22, 2019
@kusor
Copy link
Contributor

kusor commented Oct 30, 2019

Done as of PR #86

@kusor kusor closed this Oct 30, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants