Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[UPDATE] - Yarn Audit Updates #5978

Merged
merged 1 commit into from Mar 17, 2023
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Jump to
Jump to file
Failed to load files.
Diff view
Diff view
3 changes: 2 additions & 1 deletion .iyarc
@@ -1,2 +1,3 @@
GHSA-p8p7-x288-28g6
Copy link
Contributor

@legobeat legobeat Apr 21, 2023

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@sethkfman @tommasini How was the assessment made that this is not a vulnerability for MM Mobile? It looks like this can actually breaks TLS security by a protocol redirect?

This was patched in extension: MetaMask/metamask-extension#18208

If the request package is indeed staying for now, perhaps we can consider moving to the more recently maintained cypress fork with this fix: cypress-io/request#28

#excluded due NOTE: This vulnerability only affects products that are no longer supported by the maintainer. and there is no current patch
# improved-yarn-audit advisory exclusions
1085140, 1085135