garycourt / uri-js

An RFC 3986 compliant, scheme extendable URI parsing/validating/normalizing/resolving library for JavaScript
Other
305 stars 68 forks source link

CVE-2021-44906 in transitive dependency #72

Open mcharno opened 2 years ago

mcharno commented 2 years ago

There is a critical vulnerability identified in the minimist transitive dependency. See https://github.com/advisories/GHSA-xvch-5gv4-984h for more information.

tcp-mike commented 2 years ago

@garycourt can you please merge this?

fullstackzach commented 2 years ago

@garycourt Hello - please merge #71 when you get a chance, since it appears as a critical vulnerability in our project. Thanks

ruben-treams commented 2 years ago

@garycourt Another bump on this, this seems to take way too long

justin-caribou commented 1 year ago

bumping this request

andreinwald commented 6 months ago

97 - replacement for this library