Skip to content

Commit 7ff1f01

Browse files
Fix for vulnerable dependency path
nuts currently has a 5 vulnerable dependency paths, introducing 2 different types of known vulnerabilities. This PR fixes vulnerable dependencies, [remote memory exposure ](https://snyk.io/vuln/npm:request:20160119) vulnerability in the `request` dependency. You can see [Snyk test report](https://snyk.io/test/github/GitbookIO/nuts) of this project for details. This PR changes `Package.json` to upgrade `request` to the newer 2.74.0 version, and will fix the vulnerability listed above. You can get alerts and fix PRs for future vulnerabilities for free by [watching this repo with Snyk](https://snyk.io/add). Note this PR fixes all the vulnerabilities introduced trough `request` dependency, in order to be vulnerability free you will need to upgrade `octocat`,` analytics-node` and `body-parser` dependencies as well. Stay Secure, The Snyk Team
1 parent 0c2c21a commit 7ff1f01

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@
1818
"lru-diskcache": "1.1.1",
1919
"octocat": "0.10.2",
2020
"q": "1.2.0",
21-
"request": "2.60.0",
21+
"request": "2.74.0",
2222
"semver": "5.0.1",
2323
"stream-res": "1.0.1",
2424
"strip-bom": "2.0.0",

0 commit comments

Comments
 (0)