Automattic / wp-calypso

The JavaScript and API powered WordPress.com
https://developer.wordpress.com
GNU General Public License v2.0
12.42k stars 1.99k forks source link

Security alert on node-fetch@1.7.3 #48101

Open scinos opened 3 years ago

scinos commented 3 years ago

The version we use is affected by CVE-2020-15168.

This is not critical for us, because as the advisor says: "For most people, this fix will have a little or no impact. However, if you are relying on node-fetch to gate files above a size" and that is not our case.

I did a little investigation to see where node-fetch@1.73. is in our dependency tree, in case we want to eventually drop it:

github-actions[bot] commented 3 years ago

This issue is stale because it has been 180 days with no activity. You can keep the issue open by adding a comment. If you do, please provide additional context and explain why you’d like it to remain open. You can also close the issue yourself — if you do, please add a brief explanation and apply one of relevant issue close labels.