Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update request to 2.74.0 #7

Merged

Conversation

evilaliv3
Copy link
Contributor

This update is to address a security vulnerability allowing potential remote memory exposure on request<=2.68

Details:

This update is to address a security vulnerability allowing potential remote memory exposure on request<=2.68

Details:
 - https://snyk.io/vuln/npm:request:20160119
 - request/request#2018
evilaliv3 added a commit to evilaliv3/bower that referenced this pull request Jul 29, 2016
The commit bump the direct dependency request to version 2.74.0

In order for the fix to be complete the node-request-reply will have to be
updated as well as soon that IndigoUnited/node-request-replay#7
will be merged and a new package will be released.
@satazor
Copy link
Member

satazor commented Jul 29, 2016

Request is used only has a dev dep, but thanks!

@satazor satazor merged commit 99981cf into IndigoUnited:master Jul 29, 2016
@evilaliv3
Copy link
Contributor Author

you are welcome @satazor

when the main developers are vulnerable the community is vulnerable ;)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants