Skip to content

Dependency selfsigned old, creates transitive dependency on vulnerable node-forge #5617

@benknoble

Description

@benknoble

Bug Description

There are newer versions of selfsigned available with updated (or even without!) node-forge. Please consider updating this package’s dependency so vulnerable node-forge versions don’t have to be overridden downstream.

Link to Minimal Reproduction and step to reproduce

You can easily see this by examining package-lock.json after installing the latest version of this package.

Expected Behavior

Vulnerable dependencies should be updated.

Actual Behavior

Vulnerable node-forge is installed.

Environment

macOS and linux; but it shouldn’t matter here.

Is this a regression?

None

Last Working Version

No response

Additional Context

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions