Skip to content

Deprecation warning for tough-cookie due to ReDos vulnerability #1158

@codedbypaul

Description

@codedbypaul

Issue details

Installed browser sync just now and got the following warning:

npm WARN deprecated tough-cookie@2.2.2: ReDoS vulnerability parsing Set-Cookie https://nodesecurity.io/advisories/130

Steps to reproduce/test case

Install browser sync from NPM.

Please specify which version of Browsersync, node and npm you're running

  • Browsersync [ 2.14.0 ]
  • Node [ 6.3.0 ]
  • Npm [ 3.10.3 ]

Affected platforms

  • linux
  • windows
  • OS X
  • freebsd
  • solaris
  • other (please specify which)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions