Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security vulnerability in package-json v6.5.0 -> 'got' allows a redirect to a UNIX socket #17

Closed
iwt-ttaskov opened this issue Jan 11, 2023 · 1 comment
Labels

Comments

@iwt-ttaskov
Copy link

Hi everyone,

this vulnerability appears again in the as-a v2.2.2 package. Earlier you solved it here -> #15

Security vulnerability:

got: 9.6.0
├─ ID: 1080920
├─ Issue: Got allows a redirect to a UNIX socket
├─ URL: GHSA-pfrx-2q88-qq97
├─ Severity: moderate
├─ Vulnerable Versions: <11.8.5
├─ Patched Versions: >=11.8.5
├─ Via: as-a
└─ Recommendation: Upgrade to version 11.8.5 or later

as-a@2.2.2
└─┬ simple-bin-help@1.7.7
└─┬ update-notifier@5.1.0
└─┬ latest-version@5.1.0
└─┬ package-json@6.5.0
└── got@9.6.0

Please update 'got' to version 11.8.5 or above.

Thank you in advance

Copy link

🎉 This issue has been resolved in version 2.2.4 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant