Kong / unirest-nodejs

Unirest in Node.js: Simplified, lightweight HTTP client library.
http://unirest.io/nodejs
MIT License
953 stars 167 forks source link

version of unirest of kong need upgrade #125

Open unclezoro opened 5 years ago

unclezoro commented 5 years ago

For the Kong gateway, running npm audit shows one affected package

unirest needs your attention.

[ moderate ] Regular Expression Denial of Service vulnerable versions < 1.4.1 || > 2.0.0 < 2.0.3 found in:

bungle commented 5 years ago

Can you elaborate more where this happens? Kong CE at least has no unirest, and I am pretty sure we don’t package it in any of our CE packages.