ember-cli-deploy / ember-cli-deploy-s3

An ember-cli-deploy plugin to upload to s3
MIT License
53 stars 82 forks source link

Vulnerability: `vm2` via `proxy-agent` #179

Closed gorner closed 1 year ago

gorner commented 1 year ago

Raising for visibility in case this plugin's maintainers want to investigate their own solutions, or if they can clarify whether any vm2 code is actually reachable using this library. Given the timeframe before PoC disclosure, it might be OK to wait-and-see a few days before taking drastic steps.

gorner commented 1 year ago

Looks like proxy-agent has been updated to remove the vulnerability in v6.3.0 with no indication of backports (this plugin current depends on v5.0.0).