Skip to content
This repository has been archived by the owner on May 5, 2023. It is now read-only.

[security] CVE-2021-23449 - Bumped vm2 to 3.9.5 #14

Closed
wants to merge 1 commit into from

Conversation

crudo
Copy link

@crudo crudo commented Dec 20, 2021

@IndraPachipala
Copy link

Thanks @crudo for launching this PR. Snyk has identified a vulnerability with VM 3.9.3 package version. So hoping for you to merge this PR soon ?

@derekblank
Copy link

derekblank commented Feb 10, 2022

@TooTallNate This is also being reported as a critical vulnerability in our dependency chain, affecting the following packages:

 superagent-proxy@3.0.0 
  › proxy-agent@5.0.0
    › pac-proxy-agent@5.0.0
      › pac-resolver@5.0.0
        › degenerator@3.0.1
          › vm2@3.9.4

vm2@3.9.5 (and, more recently, vm2@3.9.6) contain security fixes. Any chance we could bump the vm2 dependency here?

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants