sindresorhus / ky-universal

Use Ky in both Node.js and browsers
https://github.com/sindresorhus/ky
MIT License
670 stars 20 forks source link

CVE-2022-0235 vulnerability in node-fetch #37

Closed grenik closed 2 years ago

grenik commented 2 years ago

https://github.com/sindresorhus/ky-universal/blob/ca24367ea3b5d5d4d3965396a9aeca7265011b9c/package.json#L65 has https://nvd.nist.gov/vuln/detail/CVE-2022-0235 vulnerability

Version 3.1.1 should not have it.

sindresorhus commented 2 years ago

https://github.com/sindresorhus/ky-universal/releases/tag/v0.10.0