You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The package uses nanoid 4.0 series which is vulnerable to GHSA-mwcw-c2x4-8c55.
There is a fix with version 5.0.9 which is a major release although from documentation it seem that not porting will be required. Another option is to drop it as it is used in one place so some other api can be used in place (maybe something in node:crypto)
The text was updated successfully, but these errors were encountered:
marcthe12
changed the title
nanoid verison is vulnerable to https://github.com/advisories/GHSA-mwcw-c2x4-8c55
nanoid verison is vulnerable to GHSA-mwcw-c2x4-8c55
Dec 15, 2024
It still results in the supply chain having a vulnerable dependency, which causes security tooling to complain about the risk. So, it's helpful to remove the dep on nanoid or upgrade to v5.
Definitely through, it seems harmless but it still adds noise and also has a risk. As I said, it probably does not even need to port just bump but that for the devs to verify.
The package uses nanoid 4.0 series which is vulnerable to GHSA-mwcw-c2x4-8c55.
There is a fix with version 5.0.9 which is a major release although from documentation it seem that not porting will be required. Another option is to drop it as it is used in one place so some other api can be used in place (maybe something in node:crypto)
The text was updated successfully, but these errors were encountered: