-
-
Notifications
You must be signed in to change notification settings - Fork 249
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Critical vulnerability (CVE-2023-37466) reported due to transitive dependency, vm2 which is discontinued. #2510
Comments
We don't use vm2 directly. |
You could just replace |
I'd be happy to use EDIT: ah, looks like proxy-agent dropped support for Node 12 |
Upstream dependency |
Glad you found a way to use hpagent, that alone will reduce the module size by 5MB+ 👍 Edit: Packagephobia confirms. |
🎉 This issue has been resolved in version 6.9.0 🎉 The release is available on npm package (@latest dist-tag) Your semantic-release bot 📦🚀 |
Chore summary
CVE-2023-37466
Replace dependencies resulting in the use of vm2. Instead dependencies should consider isolated-vm, recommended by the maintainer who discontinued support of vm2
Tasks
The text was updated successfully, but these errors were encountered: