apigee-127 / swagger-node-runner

The heart of Swagger-Node
MIT License
102 stars 123 forks source link

CVE/2022 24434 v2 #153

Closed jfanjoy closed 4 months ago

jfanjoy commented 4 months ago

package version was updated previously, but package-lock retained outdated dependency. When used this results in vulnerable packages being installed.

google-cla[bot] commented 4 months ago

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

jfanjoy commented 4 months ago

Mistakenly created PR. not ready.