Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability with [email protected] #594

Closed
amansanghvi opened this issue Aug 24, 2022 · 3 comments
Closed

Vulnerability with [email protected] #594

amansanghvi opened this issue Aug 24, 2022 · 3 comments
Assignees

Comments

@amansanghvi
Copy link

SDK you're using (please complete the following information):

  • Version [4.19.1, 4.23.0]

Describe the bug
Snyk on our system shows a "high" ranked vulnerability:

as this may pollute the global prototype via the validate function.

This is fixed in [email protected].

Automated advice from Snyk is:

Your dependencies are out of date, otherwise you would be using a newer json-schema than [email protected]. Try relocking your lockfile or deleting node_modules. If the problem persists, one of your dependencies may be bundling outdated modules. 
@tnzzz
Copy link
Contributor

tnzzz commented Sep 7, 2022

Hi @amansanghvi 👋 I've just started looking into this issue, and believe it is related to #579 and the deprecated request library.

@sangeet-joy-tw
Copy link
Contributor

We have updated the required packages in our new version. npm audit report is clean now.

Please use version v5.0.1

let us know with any further issues on this ticket. @amansanghvi @tnzzz

@sangeet-joy-tw sangeet-joy-tw self-assigned this Feb 8, 2024
@sangeet-joy-tw
Copy link
Contributor

Please use version v5.0.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants