parse-community / parse-server-push-adapter

A push notification adapter for Parse Server
https://parseplatform.org
MIT License
85 stars 100 forks source link

Upgrade Parse from 2.8.0 to 2.10.0 #166

Closed gnowland closed 3 years ago

gnowland commented 3 years ago

Dependency Parse should be upgraded from "2.8.0" to "2.10.0" because of security vulnerability GHSA-wvh7-5p38-2qfc affecting Parse 2.8.0

https://github.com/advisories/GHSA-wvh7-5p38-2qfc

gnowland commented 3 years ago

I see it has already been updated in package.json (PR #163) from Aug 6 - perhaps release a v3.2.1 patch to push this out asap?

davimacedo commented 3 years ago

Let's wait for https://github.com/parse-community/node-apn/pull/18 to be merged and node-apn to be published. Then we can publish a version here as well.

gnowland commented 3 years ago

v3.3.0 fixes this, closing.