Skip to content

alex transitively depends on got that has a security problem #333

Closed
@julienw

Description

@julienw

Subject of the issue

Here is the details of this security advisory:
Got allows a redirect to a UNIX socket
Package: got
Patched in: >=11.8.5
Path: alex > update-notifier > latest-version > package-json > got
More info: https://www.npmjs.com/advisories/1080920

My understanding is that package-json doesn't use the option followRedirect and therefore isn't vulnerable to this issue. Still having to look at this manually is painful, and it would be much easier if alex could update its dependency to update-notifier (they upgraded the bad dependency in sindresorhus/update-notifier#222).

Thanks

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions