jefflau / jest-fetch-mock

Jest mock for fetch
MIT License
886 stars 117 forks source link

Security vulnerability through dependency to cross-fetch > node-fetch #227

Closed Highbrainer closed 2 years ago

Highbrainer commented 2 years ago

See https://github.com/advisories/GHSA-r683-j2x4-v87g Upgrading the version of cross-fetch to the latest (3.1.5 by the timing of writing) fixes the problem.

image
diogopaulino commented 2 years ago

Hey Guys!

Any news on this?

Could you update the lib like as @Highbrainer suggested?

ghost commented 2 years ago

Hey Guys

Please update cross-fetch version >= 3.1.5

Thanks