Melipayamak / melipayamak-node

Melipayamak Nodejs samples code
17 stars 4 forks source link

melipayamak Depends on vulnerable versions of soap #12

Open HoseinGhanbari opened 1 year ago

HoseinGhanbari commented 1 year ago

It seems using old version of soap as a dependency of melipayamak-node is introducing 3 moderate severity vulnerabilities.

# npm audit report

request  *
Severity: moderate
Server-Side Request Forgery in Request - https://github.com/advisories/GHSA-p8p7-x288-28g6
fix available via `npm audit fix --force`
Will install melipayamak@1.0.0, which is a breaking change
node_modules/request
  soap  0.0.7 - 0.39.0
  Depends on vulnerable versions of request
  node_modules/melipayamak/node_modules/soap
    melipayamak  >=1.0.1
    Depends on vulnerable versions of soap
    node_modules/melipayamak

3 moderate severity vulnerabilities

To address all issues (including breaking changes), run:
  npm audit fix --force