Skip to content

Vulnerabilities in current published v3.0.2 in NPM #203

@derek-diaz

Description

@derek-diaz

Would it be possible to create a new tag for rosnodejs and push it to NPM?

Right now 3.0.2 uses a version of async that has Prototype Pollution vulnerability CVE and it also uses a version of moment that has a Path Traversal vulnerability CVE.

Both vulnerabilities have been addressed in the develop branch. The patched version of Async is now in the package.json and moment has been removed as a package.

So the only thing left is to tag and publish the NPM Package 🤞

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions