-
Notifications
You must be signed in to change notification settings - Fork 1.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
bump xml2js version to resolve CVE-2023-0842 for @azure/core-http #25502
Conversation
API change check API changes are not detected in this pull request. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good. Thanks for the PR!
…ure#25502) @azure/core-http Yes there are more than one possible design, why was the one in this PR chosen? Just bumping the dependency version Just bumping the dependency version request PRs)_ - [x] Added impacted package name to the issue description - [x] Does this PR needs any fixes in the SDK Generator?** _(If so, create an Issue in the [Autorest/typescript](https://github.com/Azure/autorest.typescript) repository and link it here)_ - [ ] Added a changelog (if necessary)
Hi, is it possible to release this security update to NPM? Many users are indirectly importing core-http through @actions/cache and getting security warnings. Thanks! |
…re/core-http (#25502) (#25518) and update release date Co-authored-by: gyz0072004 <[email protected]>
@AgustinBanchio a new version will be released today. |
@azure/core-http 3.0.1 has been published https://www.npmjs.com/package/@azure/core-http/v/3.0.1 |
Packages impacted by this PR
@azure/core-http
Issues associated with this PR
#25499
Describe the problem that is addressed by this PR
Yes
What are the possible designs available to address the problem? If there are more than one possible design, why was the one in this PR chosen?
Just bumping the dependency version
Are there test cases added in this PR? (If not, why?)
Just bumping the dependency version
Provide a list of related PRs (if any)
Command used to generate this PR:**(Applicable only to SDK release request PRs)
Checklists