Raising for visibility in case this plugin's maintainers want to investigate their own solutions, or if they can clarify whether any vm2 code is actually reachable using this library. Given the timeframe before PoC disclosure, it might be OK to wait-and-see a few days before taking drastic steps.
Raising for visibility in case this plugin's maintainers want to investigate their own solutions, or if they can clarify whether any
vm2
code is actually reachable using this library. Given the timeframe before PoC disclosure, it might be OK to wait-and-see a few days before taking drastic steps.vm2
: https://github.com/advisories/GHSA-cchq-frgv-rjh5 with PoC to be disclosed on August 8vm2
have decided they can no longer justify maintaining the library and have therefore discontinued itember-cli-deploy-s3
depends onproxy-agent
which, via a series of libraries under the same monorepo (ending withdegenerator
), depends onvm2
proxy-agent
and the other intermediate libs seems to be investigating a solution but the timeline is unclear.