-
Notifications
You must be signed in to change notification settings - Fork 3.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Vulnerability Issue reported for tough-cookie, latest version of @cypress/request is dependent of tough-cookie@2.5.0 #27261
Comments
This comment was marked as outdated.
This comment was marked as outdated.
@MikeMcC399 it should be noted that @cypress/request is affected by this: cypress-io/request#31 So I am not sure if the PR you linked is sufficient for this issue. #27005 also required the request package to be updated. |
You're right.
|
Any news or estimate on this? It seems like a very small change without many risks and the PRs are already there 🤔 I am not sure if this is something worth reporting as Security Issue. EDIT: A security issue as mail has been sent. |
NOTE: This is a temporarily work around with "overrides": {
"tough-cookie": "^4.1.3"
} Source: cypress-io/request#32 (comment) |
Edit: Now v2.88.12 has been published. |
As Thanks. |
Can you try Even a clean install of an earlier version like Cypress
Alternatively: npm update @cypress/request should also fix things. |
@MikeMcC399 note that I've opened a PR to update the advisory after which it'll get flagged by dependabot and |
Understood. This issue was just about |
Yup no worries, I just didn't want to risk losing the attention on |
Is this fixed for you now or were you expecting that Cypress would force an update to the corrected version of Line 23 in 14a7416
|
@MikeMcC399 I'm using |
Good to hear that you have the fix installed! Each of the different package managers has their own quirks! I would welcome Cypress bumping the dependency definition (see #27261 (comment)) and I was hoping for some feedback from the original contributor @Kathuria and the issue assignee @cacieprins on this topic. Without this bump there is no clear universal way to ensure that the dependency gets updated for all the different flavors of package managers. If you already have Cypress installed, updating to a newer Cypress version will not normally update the version of |
|
Agree, Dependencies upgrade would be expected fix for my requirement but open for suggestions also if any alternative way can work until the version is available through cypress patch/release. |
One alternative is to manually install |
|
You can also remove the dependency from the For completeness:
|
Edit: Superseded by |
Released in This comment thread has been locked. If you are still experiencing this issue after upgrading to |
Current behavior
It's working fine but having vulnerability issue on package @cypress/request or others consuming tough-cookie@2.5.0 which is <4.1.3
Desired behavior
Upgrade tough-cookie version to tough-cookie@4.1.3 for all packages having dependencies on this
Here is an example from latest tag, yarn-lock
"@cypress/request@^2.88.11":
version "2.88.11"
resolved "https://registry.yarnpkg.com/@cypress/request/-/request-2.88.11.tgz#5a4c7399bc2d7e7ed56e92ce5acb620c8b187047"
integrity sha512-M83/wfQ1EkspjkE2lNWNV5ui2Cv7UCv1swW1DqljahbzLVWltcsexQh8jYtuS/vzFXP+HySntGM83ZXA9fn17w==
dependencies:
aws-sign2 "~0.7.0"
aws4 "^1.8.0"
caseless "~0.12.0"
combined-stream "~1.0.6"
extend "~3.0.2"
forever-agent "~0.6.1"
form-data "~2.3.2"
http-signature "~1.3.6"
is-typedarray "~1.0.0"
isstream "~0.1.2"
json-stringify-safe "~5.0.1"
mime-types "~2.1.19"
performance-now "^2.1.0"
qs "~6.10.3"
safe-buffer "^5.1.2"
tough-cookie "~2.5.0"
tunnel-agent "^0.6.0"
uuid "^8.3.2"
Test code to reproduce
NA
Cypress Version
12.17.1
Node version
v16.15.0
Operating System
windows
Debug Logs
Other
No response
The text was updated successfully, but these errors were encountered: