aliyun / alibabacloud-oss-sdk

The OSS SDK. Powered by Darabonba.
Apache License 2.0
20 stars 8 forks source link

ts: fix CVE-2020-8237 security alert #264

Open frenchvandal opened 3 years ago

frenchvandal commented 3 years ago

嗨!你可以更新这些依赖吗?

# npm audit report

json-bigint  <1.0.0
Severity: high
Uncontrolled Resource Consumption in json-bigint - https://npmjs.com/advisories/1690
No fix available
node_modules/json-bigint
  @alicloud/credentials  1.0.0 - 1.1.0
  Depends on vulnerable versions of json-bigint
  node_modules/@alicloud/oss-baseclient/node_modules/@alicloud/credentials
    @alicloud/oss-baseclient  *
    Depends on vulnerable versions of @alicloud/credentials
    node_modules/@alicloud/oss-baseclient
      @alicloud/oss-client  *
      Depends on vulnerable versions of @alicloud/oss-baseclient
      node_modules/@alicloud/oss-client