microsoft / dev-tunnels

Dev Tunnels SDK
MIT License
297 stars 21 forks source link

Bump `es5-ext` to version 0.10.64 to resolve CVE-2024-27088 #407

Closed dmgardiner25 closed 8 months ago

dmgardiner25 commented 8 months ago

Changes proposed:

Upgrade the es5-ext package to 0.10.64 to resolve CVE-2024-27088.

I am aware of this previous PR pinning the version, but it doesn't seem like it was working as version 0.10.62 was installed which still includes the war messaging.

Other Tasks:

dmgardiner25 commented 8 months ago

Closing in favor of https://github.com/microsoft/dev-tunnels/pull/412