Skip to content

Vulnerabilities in current published v3.0.2 in NPM #203

@derek-diaz

Description

@derek-diaz

Would it be possible to create a new tag for rosnodejs and push it to NPM?

Right now 3.0.2 uses a version of async that has Prototype Pollution vulnerability CVE and it also uses a version of moment that has a Path Traversal vulnerability CVE.

Both vulnerabilities have been addressed in the develop branch. The patched version of Async is now in the package.json and moment has been removed as a package.

So the only thing left is to tag and publish the NPM Package 🤞

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions