Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature Request: Replace download dependency with node-downloader-helper or something similar to resolve CVE-2022-33987 #1090

Open
mrfigg opened this issue Apr 5, 2024 · 0 comments
Labels

Comments

@mrfigg
Copy link

mrfigg commented Apr 5, 2024

What would you like to be added:

It would be great if the download dependency could be replaced with node-downloader-helper or something similar.

Why is this needed:

This should resolve the GHSA-pfrx-2q88-qq97 warning.

The download module depends on got@^8.3.1, but issues such as kevva/download#224 seem to indicate that it is unmaintained and wont get fixed.

@mrfigg mrfigg added the feature label Apr 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant