Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability problem in Snyk #4377

Open
DamodharLRN opened this issue Jan 23, 2025 · 2 comments
Open

Vulnerability problem in Snyk #4377

DamodharLRN opened this issue Jan 23, 2025 · 2 comments

Comments

@DamodharLRN
Copy link

Hi I am checking vulnerability report of my project and I found there is one high vulnerability issue with cheerio, please suggest the solution

package details : "cheerio": "^1.0.0"
prob:

Image
@CyberFlameGO
Copy link

Yeahh - cheerio needs a version bump in honesty but if you use pnpm you could force cheerio to use a later version of undici with pnpm up --latest (or an equivalent method to update your lockfile). I'll leave these here if it's helpful though I would recommend (for security reasons) that you avoid copying my checksum

CyberFlameGO/NCEAHelpWorker@6b40cb0
Image

Image

@fb55
Copy link
Member

fb55 commented Jan 23, 2025

That patch release is within the range specified by Cheerio, so an audit fix will do the job

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

3 participants