Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerable dependencies used #891

Open
mnmohal opened this issue Oct 5, 2023 · 0 comments
Open

Vulnerable dependencies used #891

mnmohal opened this issue Oct 5, 2023 · 0 comments
Labels

Comments

@mnmohal
Copy link

mnmohal commented Oct 5, 2023

Describe the bug
Package is using old versions of child dependencies, which have vulnerability of very high severity.
One of the package is tough-cookie whose used version is V3.0.1 which is Vulnerable CVE-2023-26136 , and Its minimum version upgraded to V4.1.3

To Reproduce
Steps to reproduce the behavior:

  1. Install the npm package
  2. Observe the package-lock.json file with the child dependencies.
  3. Getting vulnerable versions of child dependencies.

Expected behavior
Latest or package with no vulnerability should be used.

Screenshots
image
image

Additional context
We are using this package from long time, due to this vulnerability in this package we have to remove this package and find an alternative, if this issue is not fixed.

@mnmohal mnmohal added the Bug label Oct 5, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant