Skip to content

Conversation

@Tofandel
Copy link

Npm audit:

simple-get  <4.0.1
Severity: high
Exposure of Sensitive Information in simple-get - https://github.com/advisories/GHSA-wpg7-2c88-r8xv
fix available via `npm audit fix --force`
Will install mongodb-client-encryption@0.2.0, which is a breaking change
node_modules/mongodb-client-encryption/node_modules/simple-get
  prebuild-install  <=6.1.4
  Depends on vulnerable versions of simple-get
  node_modules/mongodb-client-encryption/node_modules/prebuild-install
    mongodb-client-encryption  >=0.3.0
    Depends on vulnerable versions of prebuild-install
    node_modules/mongodb-client-encryption

GHSA-wpg7-2c88-r8xv

Npm audit:
```txt
simple-get  <4.0.1
Severity: high
Exposure of Sensitive Information in simple-get - GHSA-wpg7-2c88-r8xv
fix available via `npm audit fix --force`
Will install mongodb-client-encryption@0.2.0, which is a breaking change
node_modules/mongodb-client-encryption/node_modules/simple-get
  prebuild-install  <=6.1.4
  Depends on vulnerable versions of simple-get
  node_modules/mongodb-client-encryption/node_modules/prebuild-install
    mongodb-client-encryption  >=0.3.0
    Depends on vulnerable versions of prebuild-install
    node_modules/mongodb-client-encryption
```
GHSA-wpg7-2c88-r8xv
@nbbeeken
Copy link
Contributor

nbbeeken commented Feb 1, 2022

@Tofandel Thanks for bringing this to our attention, we have a number of other updates we want to perform that we'll tackle in #241 and the fix here will go out in a 2.0 release. Unfortunately it isn't possible to patch this for 1.x versions since the fixed version of prebuild-install has dropped support for node versions we still support in that release. I'll close this, but please feel free to reach out with any further questions.

@nbbeeken nbbeeken closed this Feb 1, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants