-
Notifications
You must be signed in to change notification settings - Fork 2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update dependency "follow-redirects" to mitigate CVE-2022-0536 #1571
Comments
Need this too |
Please update "follow-redirects" to >= 1.14.8 |
Need this too |
Any updates on release? |
Judging by it being nearly 2 years since I made this issue, I'm in agreeance with #1653 that this repo is unmaintained. Best option is to migrate away from this package if possible. I'll keep this issue open, even if all it serves as is a warning that this won't be solved anytime soon. |
I sort of solved it by forcing npm to use the latest version through:
No side effects for me |
@fabiohaertel Where are you adding the override? I was planning on adding it to my project's package.json like so: "overrides": {
"http-proxy": {
"follow-redirects": ">=1.15.4"
}
} If I'm not mistaken, the way you have it written will bump the version of |
Report at GHSA-pw2r-vq6v-hr8c
Recommend #1564 updates to 1.14.8 rather than 1.14.7
The text was updated successfully, but these errors were encountered: