Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot reporting security vulnerability against v2 tag #726

Closed
lacasseio opened this issue May 29, 2023 · 1 comment · Fixed by #968
Closed

Dependabot reporting security vulnerability against v2 tag #726

lacasseio opened this issue May 29, 2023 · 1 comment · Fixed by #968
Milestone

Comments

@lacasseio
Copy link

Dependabot is reporting a vulnerability on my repository despite using @v2 as shown in the README and the security advisor. The team works with Dependabot to ensure no false positives are reported on v2. If Dependabot is unwilling to fix its false positive report, then there should be a mention that Dependabot is wrong somewhere in the documentation or simply release v3 based on v2.4.2.

@bigdaz
Copy link
Member

bigdaz commented May 29, 2023

Thanks Daniel. This is a limitation with Dependabot, and I raised an issue here https://github.com/orgs/community/discussions/54553. At this stage, there's no way to use v2 and avoid the security warning: you just need to "ignore" the warning in your repository.

I've been reluctant to bump to a new major version just to avoid a bug in Dependabot, but I will certainly consider accelerating the timeframe to release version 3.x.

A PR to update the readme would be appreciated :).

@bigdaz bigdaz added this to the 3.0.0 milestone Dec 12, 2023
bigdaz added a commit that referenced this issue Dec 23, 2023
Contains all functionality planned for the initial 3.x release.

- Fixes #726 
- Fixes #946 
- Fixes #966 
- Fixes #996
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants