Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Issue with request package and CVE #127

Open
Yasholma opened this issue Jul 10, 2023 · 3 comments
Open

Issue with request package and CVE #127

Yasholma opened this issue Jul 10, 2023 · 3 comments

Comments

@Yasholma
Copy link

Have you read our Code of Conduct? By filing an Issue, you are expected to comply with it, including treating everyone with respect.

Description

I have found out there is a vulnerability issue with one of your packages
"request": "~2.88.2", this package however is out of date and no new updated will be done on it as stated here: request/request#3455, please can you consider to review this package and if possible replace it from your end ?

@orimdominic
Copy link

Hello @Yasholma Thanks for this!
It is not a good move to report security vulnerabilities via GitHub issues.
The proper way is to send a mail.
Why? This issue is public. Hackers can see it and take advantage of it.

Cheers!

@bytes-of-tsena
Copy link

bytes-of-tsena commented Dec 1, 2023

this issue's still not fixed yet. more vulnerabilities have creeped in since then. They're 4 in number.

The flutterwave maintainers should consider using one of these alternatives

reason: the maintainers of request won't maintain it anymore as stated here

@winterrdog
Copy link

if you're paranoid, you can use this instead 🤝

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants