We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
There is a CVE-2020-7598 on minimist, which is fixed in mkdirp 0.5.3 or 1.x. Adapter-node-http uses nock@11.7.2 : https://github.com/Netflix/pollyjs/blob/master/packages/%40pollyjs/adapter-node-http/package.json#L49
Could we upgrade nock@12.0.3 which removes mkdirp and so will fix the CVE ?
I don't know if this CVE is exploitable but it fails in our security scanner (Anchore) and our CISO is strict about that, no matter what.
https://nvd.nist.gov/vuln/detail/CVE-2020-7598
Node.js v12.16.1 linux 4.4.0-176-generic npm 6.13.4 yarn 1.22.4
The text was updated successfully, but these errors were encountered:
Node and npm are fixing their dependencies here :
nodejs/node#32296 npm/cli@e111676
Sorry, something went wrong.
Thanks for reporting this issue. I'll take a look first thing next week into upgrading nock.
Released with v4.0.4
v4.0.4
Thanks a lot for your quick answer !
Successfully merging a pull request may close this issue.
Description
There is a CVE-2020-7598 on minimist, which is fixed in mkdirp 0.5.3 or 1.x. Adapter-node-http uses nock@11.7.2 :
https://github.com/Netflix/pollyjs/blob/master/packages/%40pollyjs/adapter-node-http/package.json#L49
Could we upgrade nock@12.0.3 which removes mkdirp and so will fix the CVE ?
I don't know if this CVE is exploitable but it fails in our security scanner (Anchore) and our CISO is strict about that, no matter what.
Relevant Links
https://nvd.nist.gov/vuln/detail/CVE-2020-7598
Environment
The text was updated successfully, but these errors were encountered: