lquixada / cross-fetch

Universal WHATWG Fetch API for Node, Browsers and React Native.
MIT License
1.67k stars 104 forks source link

chore: updated node-fetch version to 2.6.7 #124

Closed dlafreniere closed 2 years ago

dlafreniere commented 2 years ago

Fixes CVE-2022-0235

Fixes #123

node-fetch 2.6.7 release notes

MirzetKameric commented 2 years ago

Nice one!

lquixada commented 2 years ago

thanks @dlafreniere!

dlafreniere commented 2 years ago

@lquixada can we trigger a patch release please?

lquixada commented 2 years ago

@dlafreniere it's published already! not sure why it's not reflecting on the npmjs.com page though

wbt commented 2 years ago

Any chance of getting a patch like this on the 2.x branch for all the projects still pinned to that leading to indirect vulnerabilities?