Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Updated the package es5-ext from 0.10.50 to 0.10.63 #455

Conversation

Tringapps-Dharshan
Copy link
Contributor

@Tringapps-Dharshan Tringapps-Dharshan commented Mar 7, 2024

  1. Veracode platform identifies a high-level vulnerability in the dependency package es5-ext (Dependency of WebSocket).
  2. I encountered this issue while using WebSocket version 1.0.33, which relies on es5-ext version 0.10.62.
  3. According to the npm WebSocket documentation, the latest version available is 1.0.34, released on April 14, 2021.
  4. Upon installing the latest WebSocket version, 1.0.34, I discovered it still depends on es5-ext version 0.10.62.
  5. To address this, I've updated es5-ext to version 0.10.63.
  6. I kindly request the team to merge this PR to resolve the vulnerability issue.

@lox
Copy link

lox commented May 12, 2024

Bump!

@theturtle32 theturtle32 merged commit d87afb7 into theturtle32:master May 12, 2024
@theturtle32
Copy link
Owner

Thanks for the bump! I had missed this before. Merged. Will try to do a release in the morning. 2:15am here :)

@theturtle32
Copy link
Owner

Published v1.0.35 with this fix. Thanks! Resolves #453

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants