dylang / shortid

Short id generator. Url-friendly. Non-predictable. Cluster-compatible.
https://www.npmjs.org/package/shortid
Other
5.74k stars 258 forks source link

Component Governance issue detected in the dependency "nanoid": "^2.1.0" #163

Closed VladimirTrunov closed 2 years ago

VladimirTrunov commented 2 years ago

Hello everyone,

A new Component Governance issue was generated regarding to nanoid: CVE-2021-23566

To fix this alert, we need to get nanoid updated in this library to at least 3.1.31

Thanks, -Vladimir

ai commented 2 years ago

Let’s me double check that CVE exists in 2.x. If yes, I will release a patch to 2.x branch as well.

But I highly recommend migration from shortid to nanoid.

ai commented 2 years ago

Yeap, the CVE need to be updated. It doesn’t affect 2.x. I will ask snyk team.

ai commented 2 years ago

Done. Let’s wait a week for CVE updates.