Join GitHub today
GitHub is home to over 50 million developers working together to host and review code, manage projects, and build software together.
Sign upGitHub is where the world builds software
Millions of developers and companies build, ship, and maintain their software on GitHub — the largest and most advanced development platform in the world.
Dependency vulnerability in stringstream v0.0.5 #38
Comments
|
Hi @spencern, Currently, I'm busy with some ongoing issues but certainly, I'll pick this up once I get some time. Thanks for reporting. |
|
Hi @spencern, So I looked at this issue and could see that the From the comment here, I checked on To confirm more, I also verified with NSP for any vulnerability but there was not any. See another screenshot below- Can you please check once again or share more information so that I can reproduce? |
|
This vulnerability is no longer reported via |
|
Great @spencern. |
Issue
Snyk has flagged
stringstreamv0.0.5 as a security vulnerability.https://snyk.io/vuln/npm:stringstream:20180511
Remediation
Upgrade
stringstreamto version 0.0.6 or higher.It appears that this vulnerability is pulled in via
requestv2.83.0.requestv2.86.0 and higher do not include this dependency.The text was updated successfully, but these errors were encountered: