Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Replace the deprecated and vulnerable dependency package request #47

Open
joonaojapalo opened this issue Aug 18, 2020 · 5 comments
Open

Comments

@joonaojapalo
Copy link

joonaojapalo commented Aug 18, 2020

Hi!

The direct dependency package request has been deprecated in Feb 2020 (https://www.npmjs.com/package/request). All versions of request including the latest one are affected by prototype pollution vulnerability (https://sca.analysiscenter.veracode.com/vulnerability-database/security/sca/vulnerability/sid-21913/summary)

Maintainers of the package have composed the list of alternative libraries for replacement: request/request#3143

@whtswrng
Copy link

Thank you for reporting this issue. We are now tracking this issue internally as LOG-12016.

@adarshmadrecha
Copy link

@whtswrng Any update/timeline on when the request dependency will be replaced with another suitable package?

@phawxby
Copy link

phawxby commented Mar 17, 2023

This issue is now of critical importance. GHSA-p8p7-x288-28g6

While there is a pull to address the issue there appears to be no activity from any of the maintainers to merge it.

@zdenek-machek-swi
Copy link

We are working on fix, to replace request package.

@adarshmadrecha
Copy link

Looking forward to the new release. Thanks in Advance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants