crisp-im / node-crisp-api

:zap: Crisp API Node Wrapper
https://docs.crisp.chat/guides/rest-api/
MIT License
99 stars 39 forks source link

node-fetch version is vulnerable #25

Closed marjoripomarole closed 3 years ago

marjoripomarole commented 3 years ago

This package depends on node-fetch. This issue tracks the update that needs to happen to version node-fetch@^2.6.1.

The real update would be to update fbemitter to version 3.0.0.

Relevant Github Advisory Database.

marjoripomarole commented 3 years ago

This https://github.com/crisp-im/node-crisp-api/pull/26 should fix it

baptistejamin commented 3 years ago

Thank your for the report.

We will merge this in the coming days.

eliottvincent commented 3 years ago

Merged, thanks again!

https://www.npmjs.com/package/node-crisp-api/v/1.12.1