-
Notifications
You must be signed in to change notification settings - Fork 95
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update "async" dependency #126
Comments
Any update? |
@eriktrom Any chance to get this fixed? Thanks! |
@eriktrom Friendly ping, can you look at this, thanks? |
@eriktrom I would really appreciate if you could fix this. Thanks. |
There's a PR to backport the fix to the 2.x branch on the |
Team, any status on this fix? |
I think Kiskoza's comment already addressed this. You just need to update the patch version. |
Dependabot opened #126 |
portfinder is currently using async@^2.6.2 which has a known Prototype Pollution vulnerability
async@^3.2.2 addresses this vulnerability
Additional information:
NVD: https://nvd.nist.gov/vuln/detail/CVE-2021-43138
Snyk: https://security.snyk.io/vuln/SNYK-JS-ASYNC-2441827
The text was updated successfully, but these errors were encountered: