TooTallNate / node-pac-proxy-agent

A PAC file proxy `http.Agent` implementation for HTTP and HTTPS
59 stars 57 forks source link

Can pac-resolver dependecy be upgraded? #47

Closed venuziano closed 1 year ago

venuziano commented 2 years ago

There is a high vulnerability on pac-resolver 4.1.0. See here: https://snyk.io/vuln/npm%3Apac-resolver

Could this package be upgraded to 5.0.0?

rick-aguayo commented 2 years ago

https://thehackernews.com/2022/10/researchers-detail-critical-rce-flaw.html

TooTallNate commented 1 year ago

This code in this repository has been moved to the proxy-agents monorepo, so I am closing this pull request. If you feel that this issue still exists as of the latest release, feel free to open a new issue over there.