Automattic / vip-cli

The VIP-CLI
https://docs.wpvip.com/vip-cli/
MIT License
59 stars 16 forks source link

fix: CVE-2024-29415 in `socks` #1851

Closed sjinks closed 5 months ago

sjinks commented 5 months ago

Description

This PR updates the sock package to fix the high-severity CVE-2024-29415 (ip SSRF improper categorization in isPublic).

Ref: GHSA-2p57-rm9w-gvfp

Pull request checklist

New release checklist

Steps to Test

N/A

github-actions[bot] commented 5 months ago

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails

Scanned Manifest Files

sonarcloud[bot] commented 5 months ago

Quality Gate Passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
No data about Coverage
No data about Duplication

See analysis details on SonarCloud