Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

security issues in v7 dependencies #2678

Open
willdurand opened this issue Mar 20, 2023 · 8 comments
Open

security issues in v7 dependencies #2678

willdurand opened this issue Mar 20, 2023 · 8 comments

Comments

@willdurand
Copy link
Member

> web-ext@7.5.0 audit-deps /home/circleci/web-ext
> node ./scripts/audit-deps

== audit-deps: blocking security issues

request (https://github.com/advisories/GHSA-p8p7-x288-28g6):
  2.88.2, paths: sign-addon>request
@Araxeus
Copy link

Araxeus commented Apr 20, 2023

Shame that #2688 wasn't included in the last hotfix

@willdurand any ETA for when will a new version be released?

@hymccord
Copy link

@Araxeus That wouldn't help anyhow. sign-addon 6.0.0 still depends on request 2.88.2

@willdurand
Copy link
Member Author

See also: #2822 (comment)

@aspiers
Copy link

aspiers commented May 5, 2024

It's not just request which is the issue here; sign-addon is no longer maintained.

@willdurand
Copy link
Member Author

Yeah, sign-addon is no longer maintained because we're about to release web-ext v8.

@willdurand
Copy link
Member Author

There is a new one:

jose (https://github.com/advisories/GHSA-hhhv-q57g-882q):
  4.13.1, paths: jose

@willdurand willdurand changed the title request library (via sign-addon) has a security issue security issues in v7 dependencies May 27, 2024
@Rob--W
Copy link
Member

Rob--W commented May 27, 2024

Is #3106 a duplicate of this?

@willdurand
Copy link
Member Author

Is #3106 a duplicate of this?

I think so, yeah

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

5 participants