Skip to content

[INLONG-8691][Security] Upgrade Node-Fetch Version#8698

Closed
liaosunny123 wants to merge 2 commits intoapache:masterfrom
liaosunny123:fix-8691
Closed

[INLONG-8691][Security] Upgrade Node-Fetch Version#8698
liaosunny123 wants to merge 2 commits intoapache:masterfrom
liaosunny123:fix-8691

Conversation

@liaosunny123
Copy link
Copy Markdown
Contributor

@liaosunny123 liaosunny123 commented Aug 10, 2023

Prepare a Pull Request

(Change the title refer to the following example)

  • Title Example: [INLONG-XYZ][Component] Title of the pull request

(The following XYZ should be replaced by the actual GitHub Issue number)

Motivation

Upgrade Node-Fetch Version to avoid the security problems.

Modifications

Upgrade Node-Fetch Version

Verifying this change

(Please pick either of the following options)

  • This change is a trivial rework/code cleanup without any test coverage.

  • This change is already covered by existing tests, such as:
    (please describe tests)

  • This change added tests and can be verified as follows:

    (example:)

    • Added integration tests for end-to-end deployment with large payloads (10MB)
    • Extended integration test for recovery after broker failure

Documentation

  • Does this pull request introduce a new feature? (yes / no)
  • If yes, how is the feature documented? (not applicable / docs / JavaDocs / not documented)
  • If a feature is not applicable for documentation, explain why?
  • If a feature is not documented yet in this PR, please create a follow-up issue for adding the documentation

@leezng
Copy link
Copy Markdown
Member

leezng commented Aug 14, 2023

node-fetch is a dependency of umi-request, so it is a sub-dependency of this project, we should not write it directly into package.json, which may cause version conflicts.
I suggest that the best solution to this problem is to wait for the direct dependencies to be upgraded.

@github-actions
Copy link
Copy Markdown

This PR is stale because it has been open for 60 days with no activity.

@github-actions github-actions bot added the stage/stale Issues or PRs that had no activity for a long time label Oct 14, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

component/dashboard stage/stale Issues or PRs that had no activity for a long time

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Improve][Security] The size option isn't honored after following a redirect in node-fetch

3 participants