Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump dependency due to a vulnerable package #255

Open
anaezes opened this issue Jul 12, 2024 · 1 comment · May be fixed by #256
Open

Bump dependency due to a vulnerable package #255

anaezes opened this issue Jul 12, 2024 · 1 comment · May be fixed by #256

Comments

@anaezes
Copy link

anaezes commented Jul 12, 2024

A dependency used in this project @apidevtools/json-schema-ref-parser is vulnerable to a prototype pollution attack, as listed in https://nvd.nist.gov/vuln/detail/CVE-2024-29651 - GHSA-5f97-h2c2-826q

We should bump this dependency in order to avoid any potential vulnerabilities, and to prevent vulnerability alarms by automated CVE analysis in this project.

@jayvdb
Copy link

jayvdb commented Sep 18, 2024

Noting that this project currently is pinning @apidevtools/[email protected] , which is not in the vulnerable range of the CVE.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants