Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Resolve node-fetch@^2.3.0 to 2.6.7 to fix security vulnerability GHSA-r683-j2x4-v87g #1198

Closed
wants to merge 1 commit into from

Conversation

jonny133
Copy link

@jonny133 jonny133 commented Jan 24, 2022

Resolve node-fetch@^2.3.0 to 2.6.7 to fix GHSA-r683-j2x4-v87g

Removed from package.json as it did not prevent node-fetch@^2.3.0 resolving 2.3.0 and is not necessary now.

Update the types to latest 2.x as well

@jonny133 jonny133 changed the title Resolve node-fetch to 2.6.7 to fix security vulnerability GHSA-r683-j2x4-v87g Resolve node-fetch@^2.3.0 to 2.6.7 to fix security vulnerability GHSA-r683-j2x4-v87g Jan 24, 2022
@unfernandito
Copy link
Contributor

Hello @orta

Coul be merged this PR and launch a new release?

Thanks.

@orta
Copy link
Member

orta commented Jan 29, 2022

Yep 👍🏻

@orta
Copy link
Member

orta commented Jan 29, 2022

This PR removes node-fetch from the deps, given that we use it - that does not seem like the right answer

@orta
Copy link
Member

orta commented Jan 29, 2022

Strange, it did merge but the PR is still open, so I'll manually close

@orta orta closed this Jan 29, 2022
@orta
Copy link
Member

orta commented Jan 29, 2022

OK, that's shipped in 10.9.0

glensc pushed a commit to glensc/danger-js that referenced this pull request Mar 16, 2022
Resolve node-fetch@^2.3.0 to 2.6.7 to fix security vulnerability GHSA-r683-j2x4-v87g
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants