-
Notifications
You must be signed in to change notification settings - Fork 476
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Critical Security Patch url-parse 1.5.10 #674
Comments
I updated it locally and ran the tests and they all passed. |
We're blocked on that issue. Do you have ETA? |
On your project try the command This shouldn't create any breaking changes. I applied this fix for my project and now I'm waiting for the fix to be applied to amqplib. |
Do you have any idea when do you will release a new version with a fix for this issue? |
Any update?? |
This PR is blocked by CI failing. Anyone who could contribute fix for that would be very welcome. |
The change has been merged in. See PR-675 |
@suhail-n, we need the fix in the original branch. any ETA? |
The change should be in main branch. My merge was successful. That's why I closed it. |
thanks |
Problem
The current url-parse version 1.5.3 has the following critical vulnerabilities CVE-2022-0691, and CVE-2022-0686
Fix
This problem has been resolved in [email protected]
Change package.json from
to:
The text was updated successfully, but these errors were encountered: