Skip to content

Consider forking or moving off sockjs to resolve GHSA-w5hq-g745-h8pq #5662

@G-Rath

Description

@G-Rath

sockjs is pulling in an old version of uuid which is considered vulnerable to GHSA-w5hq-g745-h8pq.

While in practice this is not actually exploitable given how prevalent webpack is, this is going to be very noisy - the dependency itself is being pulled in by sockjs which has not had a release in 5 years, and the last change was landed 8 months ago.

I'm hoping it is still maintained so I've opened sockjs/sockjs-node#315 but in the case it isn't then the library will need to be forked or replaced

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions