Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical security vulnerability - axios #3

Open
mosoriob opened this issue May 3, 2021 · 2 comments
Open

Critical security vulnerability - axios #3

mosoriob opened this issue May 3, 2021 · 2 comments
Assignees

Comments

@mosoriob
Copy link
Contributor

mosoriob commented May 3, 2021

warning serverless > @serverless/enterprise-plugin > @serverless/platform-client > [email protected]:
 Critical security vulnerability fixed in v0.21.1. For more information, see https://github.com/axios/axios/pull/3410
@mosoriob
Copy link
Contributor Author

mosoriob commented May 6, 2021

@summer7xinting can you fix it, please?

@dnfeldman
Copy link
Collaborator

@mosoriob where do you see that warning? The 3.1.2 version of @serverless/enterprise-plugin that is currently running doesn't seem to use axios. That dependency was introduced at some point between 3.1.2 and 3.8.4. Also, the newest version depends on problematic version of axios (0.19.2).

Since the current version of dcat doesn't have the vulnerability, perhaps we can leave it as it is and wait until @serverless/enterprise-plugin updates its default axios dependency to v0.21.1?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants