Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Package upgrades to fix vulnerabilities #42

Merged
merged 1 commit into from
May 8, 2023
Merged

Conversation

RyanHipkiss
Copy link
Contributor

Upgrades packages to fix security vulnerabilities. There are currently 3 vulnerabilities that haven't been fixed in this. One is moderate with the request package, and another 2 critical in the vm2 package. These are sub dependencies used by some packages we use.

I've looked into these getting fixed, and with the vm2 issues, there is an issue open right now awaiting merge which ensures we use the latest version which has the security fix included. See here.

The request issue looks a little less likely, although there is a PR awaiting merge, it seems that the package is no longer supported. I don't think there's anything we can do with this as its included by firebase-tools. See PR here

@RyanHipkiss RyanHipkiss changed the title - Package upgrades to fix vulnerabilities Package upgrades to fix vulnerabilities Apr 18, 2023
@ryanolee ryanolee merged commit 2703b41 into main May 8, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants