garris / BackstopJS

Catch CSS curve balls.
http://backstopjs.org
MIT License
6.79k stars 605 forks source link

Please upgrade puppeteer version to fix high audit severity vulnerability with `https-proxy-agent` #1104

Open shane123qaz opened 5 years ago

shane123qaz commented 5 years ago

High|Machine-In-The-Middle

Package | https-proxy-agent Patched in | >=3.0.0 Dependency of | backstopjs [dev] Path | backstopjs > puppeteer > https-proxy-agent More info | https://nodesecurity.io/advisories/1184

Please upgrade puppeteer version to fix high audit severity vulnerability with https-proxy-agent.

Akiharanza commented 5 years ago

Puppeteer haven't released the version with it on yet. Here is their issue:

https://github.com/GoogleChrome/puppeteer/issues/5055

garris commented 5 years ago

Will bump as soon as the release goes out. Thanks!