Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dependencies upgrade of module superagent due to a public vulnerability #410

Closed
bhavishraj opened this issue Apr 24, 2024 · 2 comments
Closed
Labels
type: security Security issues/fixes.

Comments

@bhavishraj
Copy link

Versions

  • Node: 20.1.0
  • Libhoney: 4.2.0

Description

Dependent module superagent had a public vulnerability with formidable dependency in version 8, and hence have released v9.0.0+ with the fix.
More info is present in the link: ladjs/superagent#1800
Can you please look into it and upgrade dependency for superagent accordingly.
(Please include any relevant CVE advisory links)

@MikeGoldsmith
Copy link
Contributor

MikeGoldsmith commented Apr 25, 2024

Thanks for creating the issue @bhavishraj - we've been waiting for superagent to resolve their security issue but took a while due their package dependency chain.

@MikeGoldsmith
Copy link
Contributor

Hi @bhavishraj - libhoney 4.3.0 has now been released with the updated superagent dependency.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type: security Security issues/fixes.
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants