Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

HOFF 694 Upgrade notifications node client to 8.0.0 #447

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

TemitopeAyokuHO
Copy link

@TemitopeAyokuHO TemitopeAyokuHO commented Apr 5, 2024

##What
HOFF-694 Security upgrade notifications-node-client from 6.0.0 to 8.0.0

Why?

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 676/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.1
Cross-site Request Forgery (CSRF)
SNYK-JS-AXIOS-6032459
Yes Proof of Concept

How?

  • updated the version number in package.json
  • change in the yarn file

@TemitopeAyokuHO TemitopeAyokuHO force-pushed the HOFF-694-Security-upgrade-notifications-node-client-from-6.0.0-to-8.0.0 branch from 7d87cd7 to 62b0d13 Compare April 5, 2024 09:20
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    - package.json
@TemitopeAyokuHO TemitopeAyokuHO force-pushed the HOFF-694-Security-upgrade-notifications-node-client-from-6.0.0-to-8.0.0 branch from 62b0d13 to 8e9ee69 Compare April 5, 2024 09:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant