Hilscher / node-red-contrib-s7comm

A Node-RED node to communicate with Siemens S7 PLCs.
MIT License
34 stars 11 forks source link

Node.js Package: node-addon-api ≤ 1.7.1, 2.0.0 - Remote Code Execution Vulnerability - 1.7.2, 2.0.1 #9

Open RMutharaju opened 4 years ago

RMutharaju commented 4 years ago

Hello,

I see a vulnerability reported with node-addon-api - (because of DevDependencies)

Refer: https://snyk.io/vuln/SNYK-JS-NODEADDONAPI-571001

This has been addressed by net-keepalive https://github.com/hertzg/node-net-keepalive/pull/25

Kindly upgrade the node version. Thanks.