Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

security issue with https-proxy-agent package #578

Open
3 of 9 tasks
sshaar08 opened this issue Oct 18, 2019 · 2 comments
Open
3 of 9 tasks

security issue with https-proxy-agent package #578

sshaar08 opened this issue Oct 18, 2019 · 2 comments

Comments

@sshaar08
Copy link

sshaar08 commented Oct 18, 2019

Description

Describe your issue here.

┌──────────────────────────────────────────────────────────────────────────────┐
│                                Manual Review                                 │
│            Some vulnerabilities require your attention to resolve            │
│                                                                              │
│         Visit https://go.npm.me/audit-guide for additional guidance          │
└──────────────────────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High          │ Machine-In-The-Middle                                        │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ https-proxy-agent                                            │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ >=3.0.0                                                      │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ hubot-slack                                                  │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ hubot-slack > @slack/client > https-proxy-agent              │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://nodesecurity.io/advisories/1184

What type of issue is this? (place an x in one of the [ ])

  • bug
  • enhancement (feature request)
  • question
  • documentation related
  • testing related
  • discussion

Requirements (place an x in each of the [ ])

  • I've read and understood the Contributing guidelines and have done my best effort to follow them.
  • I've read and agree to the Code of Conduct.
  • I've searched for any related issues and avoided creating a duplicate issue.

Bug Report

Filling out the following details about bugs will help us solve your issue sooner.

Reproducible in:

hubot-slack version: 4.7.1

node version:

OS version(s):

Steps to reproduce:

Expected result:

What you expected to happen

Actual result:

What actually happened

Attachments:

Logs, screenshots, screencast, sample project, funny gif, etc.

@seratch seratch self-assigned this Apr 14, 2020
@seratch seratch changed the title security issue https=proxy-agent security issue with https-proxy-agent package Apr 14, 2020
@seratch
Copy link
Member

seratch commented Apr 14, 2020

Making a pull request to node-slack-sdk 's v3 branch like slackapi/node-slack-sdk#621 is required to fix this issue.

For reference: here is the output by npm ls with the latest revision of hubot-slack and node-slack-sdk.
npm-ls.log

@seratch seratch removed their assignment Apr 14, 2020
@github-actions
Copy link

github-actions bot commented Dec 5, 2021

👋 It looks like this issue has been open for 30 days with no activity. We'll mark this as stale for now, and wait 10 days for an update or for further comment before closing this issue out.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants