Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Issue with dependent package undici #10140

Closed
techy2493 opened this issue Feb 20, 2024 · 1 comment
Closed

Security Issue with dependent package undici #10140

techy2493 opened this issue Feb 20, 2024 · 1 comment

Comments

@techy2493
Copy link

techy2493 commented Feb 20, 2024

Which package is this bug report for?

discord.js

Issue description

I cannot upgrade to 14.14.1 because of an upstream dependency of the latest version adding security vulnerability.

image

For more info see Github's Dependabot's PR to my repo bumping discord.js to latest. This is the only change in this repo which means this dependency is coming from discord.js somewhere between my current version 14.7.1 and 14.14.1

techy2493/ts-disc-control#35

Code sample

No response

Versions

discord.js 14.14.1

Issue priority

Medium (should be fixed soon)

Which partials do you have configured?

Not applicable

Which gateway intents are you subscribing to?

Not applicable

I have tested this issue on a development release

No response

@toast-ts
Copy link
Contributor

There's nothing that Discord.js can do at the moment, other than you dismissing the alert.
Also, it was already brought up in another issue:
#10132 (comment)

@almostSouji almostSouji closed this as not planned Won't fix, can't repro, duplicate, stale Feb 20, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants