Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Request: upgrade dependency Snappy #1457

Open
DesmondHsu opened this issue Oct 14, 2021 · 2 comments
Open

Request: upgrade dependency Snappy #1457

DesmondHsu opened this issue Oct 14, 2021 · 2 comments

Comments

@DesmondHsu
Copy link

Snappy 6.0.1 contains tar 6.1.0 which has several potential vulnerabilities - Arbitrary File Write, Regular Expression Denial of Service (ReDoS)

Doesn't seem to have issue upgrading to Snappy 7, which doesn't contain tar. Please consider.

@imsamurai
Copy link

any update?

# npm audit report

simple-get  <4.0.1
Severity: high
Exposure of Sensitive Information in simple-get - https://github.com/advisories/GHSA-wpg7-2c88-r8xv
node_modules/simple-get
  prebuild-install  <=6.1.4
  Depends on vulnerable versions of simple-get
  node_modules/prebuild-install
    snappy  6.1.0 - 6.3.5
    Depends on vulnerable versions of prebuild-install
    node_modules/snappy

@rkendall-skillsoft
Copy link

Will this be addressed anytime soon?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants