Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

prototype pollution in immer (upstream security issue) #951

Closed
macrozone opened this issue Apr 8, 2021 · 3 comments
Closed

prototype pollution in immer (upstream security issue) #951

macrozone opened this issue Apr 8, 2021 · 3 comments

Comments

@macrozone
Copy link
Collaborator

currently, there is an unfixed upstream security issue in slate: ianstormtaylor/slate#4066 because of the version of immer that is used.

not much we can do at the moment. We try to update it as soon as there is some news.

@macrozone macrozone added the bug label Apr 8, 2021
@macrozone
Copy link
Collaborator Author

its a bit ambigous whether this has been fixed in slate, but looks like.

there is still a PR that we can continue on (#890)

and bump there the slate version to latest.

I will probably do that this week.

macrozone added a commit that referenced this issue Jun 1, 2021
macrozone added a commit that referenced this issue Jun 1, 2021
this also updates immer which had a prototype pollution

fixes #951
@macrozone
Copy link
Collaborator Author

🎉 This issue has been resolved in version 2.3.0-beta.1 🎉

The release is available on:

Your semantic-release bot 📦🚀

@macrozone
Copy link
Collaborator Author

🎉 This issue has been resolved in version 2.3.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant