Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency to fix vulnerability #44

Closed
idris-maps opened this issue Feb 17, 2020 · 7 comments
Closed

Update dependency to fix vulnerability #44

idris-maps opened this issue Feb 17, 2020 · 7 comments
Assignees

Comments

@idris-maps
Copy link

Client version

4.3.0

Expected behaviour

No vulnerabilities

Actual behaviour

Screenshot from 2020-02-17 14-33-42

Steps to reproduce

npm install
@demoore demoore self-assigned this Feb 17, 2020
@demoore
Copy link
Member

demoore commented Feb 17, 2020

Thanks for reporting this @idris-maps. We'll update this as soon as this has been merged into the HTTP client this package uses: danwrong/restler#263

@vuhrmeister
Copy link

Are you confident that it will? The last commit is from 2015 and there are a lot of outstanding Pull Requests.

@idris-maps
Copy link
Author

It seems to be a library to do HTTP requests. Maybe it makes sense to use something that is actively maintained. Maybe axios

@demoore
Copy link
Member

demoore commented Feb 18, 2020

Yeah, that's a good point. I don't think we're able to rewrite the client with a different dependency soon. I wonder if we can vendor restler and and update the package the vulnerability?

@tday
Copy link

tday commented Apr 16, 2020

Any updates on this? Seems just a few steps away given you've forked and patched

@demoore
Copy link
Member

demoore commented Apr 24, 2020

Thank you for your patience, folks. We've released a new version with a patched version of restler.

@demoore demoore closed this as completed Apr 24, 2020
@tday
Copy link

tday commented Apr 25, 2020

Thanks so much for the patch! @demoore 👏

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants