Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(runtime): update node-fetch from ^2.6.1 to ^2.6.7 #2041

Merged
merged 2 commits into from Jan 31, 2022

Conversation

crudo
Copy link
Contributor

@crudo crudo commented Jan 27, 2022

Checklist

  • Tests added / updated
  • Docs added / updated

Does this PR introduce a breaking change?

  • Yes
  • No

If indicated yes above, please describe the breaking change(s).

Screenshots

n/a

Additional context

GHSA-r683-j2x4-v87g
node-fetch/node-fetch#1453
https://nvd.nist.gov/vuln/detail/CVE-2022-0235

@P0lip P0lip changed the title [Security] CVE-2022-0235 update node-fetch@2.6.7 fix(runtime): update node-fetch from ^2.6.1 to ^2.6.7 Jan 31, 2022
Copy link
Contributor

@P0lip P0lip left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@P0lip P0lip added security Pull requests that address a security vulnerability dependencies Pull requests that update a dependency file labels Jan 31, 2022
@P0lip P0lip enabled auto-merge (squash) January 31, 2022 21:31
@P0lip P0lip merged commit 869510f into stoplightio:develop Jan 31, 2022
stoplight-bot pushed a commit that referenced this pull request Feb 1, 2022
# [@stoplight/spectral-runtime-v1.1.2](https://github.com/stoplightio/spectral/compare/@stoplight/spectral-runtime-v1.1.1...@stoplight/spectral-runtime-v1.1.2) (2022-02-01)

### Bug Fixes

* **runtime:** update node-fetch from ^2.6.1 to ^2.6.7 ([#2041](#2041)) ([869510f](869510f))
@stoplight-bot
Copy link
Collaborator

🎉 This PR is included in version @stoplight/spectral-runtime-v1.1.2 🎉

The release is available on npm package (@latest dist-tag)

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file released security Pull requests that address a security vulnerability
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants