Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

vulnerability found in dependency #149

Closed
xemayebenes opened this issue Dec 23, 2020 · 5 comments
Closed

vulnerability found in dependency #149

xemayebenes opened this issue Dec 23, 2020 · 5 comments

Comments

@xemayebenes
Copy link

Last version throws audit fails

. -
Low Denial of Service
Package node-fetch
Patched in >=2.6.1 <3.0.0-beta.1
Dependency of avatax
Path avatax > isomorphic-fetch > node-fetch
More info https://npmjs.com/advisories/1556

Are you planning to fix this dependency?

@Eric-Dunaway
Copy link

@eboureau
Copy link

eboureau commented Feb 1, 2022

HI, any news on that one?
There is now a High vulnerability in node-fetch dependency, when do you plan to upgrade to isomorphic-fetch@3.0.0?

@eboureau
Copy link

eboureau commented Feb 2, 2022

I also think you should get rid of isomorphic-fetch and just use node-fetch@2.6.7. IMO isomorphic-fetch has no added value using node.js

@chelevich
Copy link

seems to be resolved by 7d87bb4

@svc-developer
Copy link
Collaborator

Resolved in 22.5.0.
Thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants