stereobooster / react-snap

👻 Zero-configuration framework-agnostic static prerendering for SPAs
MIT License
5.06k stars 394 forks source link

bump https-proxy-agent to mitigate a security issue #419

Open Mgayar-sci opened 4 years ago

Mgayar-sci commented 4 years ago

Bug Report

Current Behavior Security issue discovered in http-proxy-agent <3.0 https://app.snyk.io/test/npm/https-proxy-agent/2.2.2

Reproducible demo https://github.com/GoogleChrome/puppeteer/commit/5b34028e63c9532349ac525fa4c14daeada05b94

Expected behavior/code

Possible Solution bump puppeteer version to the latest version

Additional context/Screenshots High Machine-In-The-Middle

Package https-proxy-agent

Patched in >=3.0.0
Path react-snap > puppeteer > https-proxy-agent

More info https://npmjs.com/advisories/1184