closeio / sync-engine

GNU Affero General Public License v3.0
25 stars 9 forks source link

Upgrade Redis library to 4.4.4 #481

Closed nsaje closed 7 months ago

nsaje commented 1 year ago

https://github.com/closeio/sync-engine/security/dependabot/18

kevinschumacher commented 8 months ago

Dependabot security issue is no longer there (withdrawn? not sure) but sync-engine uses 2.10.6

Image

Not sure if that impacts prioritization @nsaje ?

nsaje commented 8 months ago

It doesn't, we should still do this. It's not there because we ignored the alert in Vanta and created this issue to track the upgrade.

It was initially postponed because sync-engine was still using Redis v3 or something and we had to upgrade it to v7 first before upgrading this lib.