-
Notifications
You must be signed in to change notification settings - Fork 538
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update tough-cookie indirect dependency to version >=4.1.3 #1381
Comments
Hey @tiagodarosa, Can you share more details about that ? |
We are currently in the process of removing request as a dependency but it's not yet ready to release. In order to see the progress of the 1.x branch you can have a look here: https://github.com/kubernetes-client/javascript/blob/release-1.x/FETCH_MIGRATION.md or here #754 which both should contain the latest information. I'll close this as a duplicate of #754 as we would need to remove request for this. What you could try is to manually override the dependency in |
The path to deprecate the request library is documented here: #414 I'm going to close this issue in favor of that issue. Updated: Oops, my github page was stale and I didn't see @mstruebing comments above which gives much more details :) |
Thank you @brendandburns @mstruebing @professorabhay for your attention! I'll try the 1.0.0rc version! |
Describe the bug
The
tough-cookie
indirect dependency has a security vulnerability. Please check here https://security.snyk.io/vuln/SNYK-JS-TOUGHCOOKIE-5672873 and here salesforce/tough-cookie#282 and update to a version >= 4.1.3. This may require removingrequest
as it is already deprecated request/request#3142.** Client Version **
0.19.0
The text was updated successfully, but these errors were encountered: