-
-
Notifications
You must be signed in to change notification settings - Fork 163
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ws dependency package vulnerability: CVE-2024-37890 #564
Labels
dependencies
Pull requests that update a dependency file
Comments
A PR is very welcome! Not urgent though since |
enisdenjo
added
dependencies
Pull requests that update a dependency file
and removed
enhancement
New feature or request
labels
Aug 29, 2024
This is throwing off some warnings for us, I'll submit a PR shortly. |
My PR will reference only the top-level ws dependency. Consider leaving this issue open if you are wanting to fix the rest in the tree. Some (like subscriptions-transport-ws) are not possible to fix via an upgrade as they are not actively maintained.
|
2 tasks
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Upgrading to
[email protected]
or later should work. The package is currently hard coded to8.12.0
.More info: https://github.com/advisories/GHSA-3h5v-q93c-6h6q
The text was updated successfully, but these errors were encountered: