zkat / make-fetch-happen

Get in loser, we're making requests!
Other
384 stars 27 forks source link

Update https-proxy-agent to current version #71

Closed mearleycf closed 6 months ago

mearleycf commented 5 years ago

https://npmjs.com/advisories/1184 There is a machine in the middle attack possible with version 2.2.1 of https-proxy-agent. Please upgrade to the current version.

szellcsaba-ge commented 5 years ago

@zkat bump.

mearleycf commented 5 years ago

Any movement on merging this?

philipmckenna commented 5 years ago

Since this project has the package-lock in source control as well then can you run the npm install and commit the updated package-lock.json. Should help with the travis CI build npm ERR! Invalid: lock file's https-proxy-agent@2.2.1 does not satisfy https-proxy-agent@^3.0.0