Closed
Description
Subject of the issue
Here is the details of this security advisory:
Got allows a redirect to a UNIX socket
Package: got
Patched in: >=11.8.5
Path: alex > update-notifier > latest-version > package-json > got
More info: https://www.npmjs.com/advisories/1080920
My understanding is that package-json doesn't use the option followRedirect
and therefore isn't vulnerable to this issue. Still having to look at this manually is painful, and it would be much easier if alex could update its dependency to update-notifier
(they upgraded the bad dependency in sindresorhus/update-notifier#222).
Thanks
Metadata
Metadata
Assignees
Labels
No labels