Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Replace the deprecated and vulnerable dependency package `request` #47

Open
joonaojapalo opened this issue Aug 18, 2020 · 0 comments
Open

Replace the deprecated and vulnerable dependency package `request` #47

joonaojapalo opened this issue Aug 18, 2020 · 0 comments

Comments

@joonaojapalo
Copy link

@joonaojapalo joonaojapalo commented Aug 18, 2020

Hi!

The direct dependency package request has been deprecated in Feb 2020 (https://www.npmjs.com/package/request). All versions of request including the latest one are affected by prototype pollution vulnerability (https://sca.analysiscenter.veracode.com/vulnerability-database/security/sca/vulnerability/sid-21913/summary)

Maintainers of the package have composed the list of alternative libraries for replacement: request/request#3143

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
1 participant
You can’t perform that action at this time.