-
Notifications
You must be signed in to change notification settings - Fork 24
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Remove "request" dependency due to security vulnerability? CVE-2023-28155 #51
Comments
Looks like it's not even used in the repository. Was it just forgotten in the deps? |
Looks like this was addressed here: #60 Just needs a release cutting from |
Thank you for letting us know - release is triggerd! Closing issue |
Looks like tests are failing: https://github.com/ory/integrations/actions/runs/8434909650/job/23099169259 Would appreciate help fixing the issues! |
Tests pass locally on node 21, GitHub Actions are on 17.. do you want to upgrade, or fix the test on 17? |
The version of next used on |
The dependency "request" has a security vulnerability (reported by npm audit):
GHSA-p8p7-x288-28g6
The "request" library itself is deprecated:
request/request#3142
There is a PR on the project to fix the vulnerability, but it looks like it will not be merged:
request/request#3444
The text was updated successfully, but these errors were encountered: