node-apn / node-apn

:calling: Apple Push Notification module for Node.js
MIT License
4.37k stars 681 forks source link

Security alert: upgrade node-forge to 0.10.0 #698

Open gaillota opened 3 years ago

gaillota commented 3 years ago

I had this popping up in my repo a few days ago, just wanted to let you know

Screenshot 2020-12-30 at 00 25 08

Can we update node-forge or is that breaking ? I have no idea if you guys already know or if someone is already on it ? Just let me know :)

ewan-spence commented 3 years ago

I'm having the same issue, NPM is calling it a high severity vulnerability.

Will APN work with Node-Forge > 0.7.6? Or will we just have to have the vulnerability?

balzafin commented 3 years ago

There seems to be an open PR already https://github.com/node-apn/node-apn/pull/684. Has been open since September though.

danthegoodman1 commented 3 years ago

https://github.com/danthegoodman1/node-apn if anyone wants to use an updated fork