Skip to content

v0.8.1

Compare
Choose a tag to compare
@lucaswerkmeister lucaswerkmeister released this 12 Nov 15:01
· 31 commits to main since this release
  • Updated undici, avoiding CVE-2023-45143. The potential impact of this security vulnerability should have been very low: when using the fetch-node backend and a cookie-based session type, an attacker with the ability to create an open redirect on the target API could potentially have obtained session cookies for the API. (I see no reason to expect an open redirect vulnerability to exist in the action API: I’m not aware of any API action that issues HTTP-level redirects at all.)
  • Updated dependencies.