-
Notifications
You must be signed in to change notification settings - Fork 20
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Replace the deprecated and vulnerable dependency package request
#47
Comments
Thank you for reporting this issue. We are now tracking this issue internally as LOG-12016. |
@whtswrng Any update/timeline on when the |
This issue is now of critical importance. GHSA-p8p7-x288-28g6 While there is a pull to address the issue there appears to be no activity from any of the maintainers to merge it. |
We are working on fix, to replace |
Looking forward to the new release. Thanks in Advance. |
Hi!
The direct dependency package
request
has been deprecated in Feb 2020 (https://www.npmjs.com/package/request). All versions ofrequest
including the latest one are affected by prototype pollution vulnerability (https://sca.analysiscenter.veracode.com/vulnerability-database/security/sca/vulnerability/sid-21913/summary)Maintainers of the package have composed the list of alternative libraries for replacement: request/request#3143
The text was updated successfully, but these errors were encountered: