allbridge-io / allbridge-core-js-sdk

20 stars 10 forks source link

tough-cookie Prototype Pollution vulnerability #86

Open myz1237 opened 1 month ago

myz1237 commented 1 month ago

Describe the bug I have enabled dependency bot in my repo, and got the alert: tough-cookie Prototype Pollution vulnerability. Any plan to update the version of tough-cookie you are using? Thanks

To Reproduce Steps to reproduce the behavior:

1. 2. 3.

Expected behavior A clear and concise description of what you expected to happen.

Screenshots

image

Desktop (please complete the following information):

Additional context Add any other context about the problem here.

opanasiuk-oleksii commented 1 month ago

@myz1237 thanks for pointing. I will tag you, pointing to the release version that contains a fix when it's ready.

myz1237 commented 1 month ago

appreciate