-
-
Notifications
You must be signed in to change notification settings - Fork 91
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
v6: CVE-2021-23386: update dns-packet #75
Comments
It's already fixed for v6 if you reinstall deps, I backported it on dns-packet to the version multicast-dns 6 is tracking :) |
@mafintosh If you could make that known to the advisory, it might work. See https://www.npmjs.com/advisories/1745/versions |
I already did |
Sounds great! Is this already available on npm? At least for me |
dns-packet is where the update is. multicast-dns v6 tracks v1 which is where i backported the fix. do you know if i need to backport a version bump to multicast-dns as well for this security sillyness to stop? |
fyi this is the dns-packet backport https://github.com/mafintosh/dns-packet/tree/v1 |
Ah, awesome. Thank your for fixing it at the very source! |
I sent SNYK an email bump now also to get them to update the advisory |
Can you please confirm that
Thanks. |
advisory is updated, just checked |
Thank you for bumping
dns-packet
in #74 for version 7.Could you also release a security bump for version 6? This currently affects
webpack-dev-server
via a different (no longer maintained) library, that still makes use ofmulticast-dns
version6
:https://github.com/watson/bonjour/blob/bdc467a4f3c7b9fe8bc54468b6fc4d80b8f1c098/package.json#L11
More details can be found at webpack/webpack-dev-server#3340.
The text was updated successfully, but these errors were encountered: