Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bump vulnerable ua-parser-js version #4343

Merged
merged 1 commit into from
Oct 26, 2021
Merged

Conversation

hom3chuk
Copy link

There's a malicious ua-parser-js NPM takeover, this PR bumps ua-parser-js version to the safe 0.7.30.

Security advisory: GHSA-pjwm-rvh2-c87w
GH thread: faisalman/ua-parser-js#536

@itsjohncs
Copy link
Member

The version we're currently at (0.7.28) is not compromised.

@hom3chuk
Copy link
Author

7.30 is effectively the same as 7.28, it's just a matter of jumping over compromised version to minimise possible damage when upgrading in future or someone deciding to try out one minor version higher during development.

faisalman/ua-parser-js@0.7.30...0.7.28

But it's good with me if you folks keep an eye on the repo and just leave it @ 7.28! 🤓

@MaxLeiter MaxLeiter merged commit 97f3800 into thelounge:master Oct 26, 2021
@MaxLeiter
Copy link
Member

Thanks @hom3chuk! But yeah, as John said, we aren't compromised and we pin our versions to (try to) avoid being affected by problems like this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants