Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bump xml2js version to resolve CVE-2023-0842 for @azure/core-http #25502

Merged
merged 2 commits into from
Apr 10, 2023

Conversation

gyz0072004
Copy link
Member

@gyz0072004 gyz0072004 commented Apr 10, 2023

Packages impacted by this PR

@azure/core-http

Issues associated with this PR

#25499

Describe the problem that is addressed by this PR

Yes

What are the possible designs available to address the problem? If there are more than one possible design, why was the one in this PR chosen?

Just bumping the dependency version

Are there test cases added in this PR? (If not, why?)

Just bumping the dependency version

Provide a list of related PRs (if any)

Command used to generate this PR:**(Applicable only to SDK release request PRs)

Checklists

  • Added impacted package name to the issue description
  • Does this PR needs any fixes in the SDK Generator?** (If so, create an Issue in the Autorest/typescript repository and link it here)
  • Added a changelog (if necessary)

@ghost ghost added the Azure.Core label Apr 10, 2023
@gyz0072004 gyz0072004 changed the title bump xml2js version to resolve CVE-2023-0842 bump xml2js version to resolve CVE-2023-0842 for @azure/core-http Apr 10, 2023
@azure-sdk
Copy link
Collaborator

API change check

API changes are not detected in this pull request.

Copy link
Member

@jeremymeng jeremymeng left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good. Thanks for the PR!

@jeremymeng jeremymeng merged commit b6ec757 into Azure:main Apr 10, 2023
jeremymeng pushed a commit to jeremymeng/azure-sdk-for-js that referenced this pull request Apr 10, 2023
…ure#25502)

@azure/core-http

Yes

there are more than one possible design, why was the one in this PR
chosen?
Just bumping the dependency version

Just bumping the dependency version

request PRs)_

- [x] Added impacted package name to the issue description
- [x] Does this PR needs any fixes in the SDK Generator?** _(If so,
create an Issue in the
[Autorest/typescript](https://github.com/Azure/autorest.typescript)
repository and link it here)_
- [ ] Added a changelog (if necessary)
@AgustinBanchio
Copy link

Hi, is it possible to release this security update to NPM?
Is there a release schedule?

Many users are indirectly importing core-http through @actions/cache and getting security warnings.

Thanks!

jeremymeng added a commit that referenced this pull request Apr 11, 2023
…re/core-http (#25502) (#25518)

and update release date

Co-authored-by: gyz0072004 <[email protected]>
@jeremymeng
Copy link
Member

@AgustinBanchio a new version will be released today.

@jeremymeng
Copy link
Member

@azure/core-http 3.0.1 has been published https://www.npmjs.com/package/@azure/core-http/v/3.0.1

jeremymeng pushed a commit that referenced this pull request Apr 17, 2023
- bump xml2js version to resolve CVE-2023-0842 for @azure/core-http (#25502)

@azure/core-http
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants