Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependencies to fix vulnerabilities #78

Merged
merged 1 commit into from
Apr 24, 2024
Merged

Conversation

tomstrong64
Copy link
Owner

@tomstrong64 tomstrong64 commented Apr 23, 2024

Fixed CVE-2024-31207 and CVE-2024-29041.
Waiting on superagent to update their dependency formidable to patch CVE-2022-29622. (ladjs/superagent#1799)

@tomstrong64
Copy link
Owner Author

I patched superagent but supertest needs to be updated to use the new version.
ladjs/superagent#1800

As supertest is a dev dependency being used for testing it is not critical that we fix it.

@tomstrong64 tomstrong64 marked this pull request as ready for review April 24, 2024 11:20
@tomstrong64 tomstrong64 added the dependencies Pull requests that update a dependency file label Apr 24, 2024
@tomstrong64 tomstrong64 merged commit 4d52332 into main Apr 24, 2024
2 checks passed
@tomstrong64 tomstrong64 deleted the security-patch branch May 13, 2024 21:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants