d-rec / drec-origin

D-REC Origin
https://d-rec.github.io/drec-origin/
GNU General Public License v3.0
8 stars 1 forks source link

Fix Required: Crash in HeaderParser in dicer #111 #327

Open Aish1990 opened 5 months ago

Aish1990 commented 5 months ago

There is an library which need dependency dicer as below.

@energyweb/origin-backend/11.0.2-alpha.1634225870.0_swagger-ui-express@4.1.6 => @nestjs/platform-express/7.6.18_ezseebmi4ciby6kdvs2gspf26q => /multer/1.4.2: => busboy/0.2.14: => dicer: 0.2.5
@energyweb/origin-backend/11.0.2-alpha.1634225870.0_swagger-ui-express@4.1.6 => multer/1.4.3 => busboy/0.2.14 =>       dicer: 0.2.5

[!NOTE] There is no updated release of dicer>0.3.1 as the dicer<=0.3.1 is vulnerable.

So We need to resolve it only when the dicer releases version >0.3.1 which is compatible with @energyweb/origin-backend and with no vulnerability.