request / request

🏊🏾 Simplified HTTP request client.
Apache License 2.0
25.67k stars 3.14k forks source link

QS Vulnerability #3450

Open joelrichardvitrana opened 1 year ago

joelrichardvitrana commented 1 year ago

Currently my "request" package is of version "2.88.2" and it requires a package - "qs" of its old version "6.5.2". This version of qs currently has a high vulnerability (https://github.com/advisories/GHSA-hrpp-h998-j3pp).

Is there any version of "request" which requires the a stable "qs" version which does not have a vulnerability. If so, could you please let us know?