Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependency on a vulnerable version of node-sass /request #162

Open
YasharF opened this issue Jul 13, 2023 · 0 comments
Open

Dependency on a vulnerable version of node-sass /request #162

YasharF opened this issue Jul 13, 2023 · 0 comments

Comments

@YasharF
Copy link

YasharF commented Jul 13, 2023

Can you please bump the dependency to the latest version of node-sass to remove the vulnerable dependency? There is a PR already there to address this: #161 . You may need to do a major version bump of the middleware because the new version of node-sass has dropped support for deprecated Node versions.

request  *
Severity: moderate
Server-Side Request Forgery in Request - https://github.com/advisories/GHSA-p8p7-x288-28g6

  node-sass  1.2.3 - 3.4.2 || 3.5.3 - 7.0.3
  Depends on vulnerable versions of request
  node_modules/node-sass-middleware/node_modules/node-sass
    node-sass-middleware  0.5.0 || >=0.10.0
    Depends on vulnerable versions of node-sass
    node_modules/node-sass-middleware
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant