mreinstein / alexa-verifier

✓ Verify HTTP requests sent to an Alexa skill are sent from Amazon
MIT License
76 stars 23 forks source link

update node-forge to fix Veracode SCA vulnerabilities #67

Closed ahitrov closed 2 years ago

ahitrov commented 2 years ago

Veracode SCA reports: https://sca.analysiscenter.veracode.com/vulnerability-database/security/sca/vulnerability/sid-33572/summary https://sca.analysiscenter.veracode.com/vulnerability-database/security/sca/vulnerability/sid-33569/summary https://nvd.nist.gov/vuln/detail/CVE-2022-0122

for node-forge upto v0.10.0 including

ahitrov commented 2 years ago

@mreinstein can you review this with priority?

mreinstein commented 2 years ago

Published to npm as 3.0.2. thanks!