Vulnerability issue in used "node-fetch" version 2.6.1 #1624
Labels
priority: p2
Moderately-important priority. Fix may not be included in next release.
type: bug
Error or flaw in code with unintended results or allowing sub-optimal usage patterns.
Hi there,
We are using google-gax in our project deployed on GCP account. in our yearly report we are getting issue with npm package node-fetch (^2.6.1) that should be update version
2.6.7
or higher.Environment details
"The library
node-fetch
version2.6.1
was detected inNPM library manager
located atpackage-lock.json
and is vulnerable toCVE-2022-0235
, which exists in versions< 2.6.7
.The vulnerability was found in the Github Security Advisory with vendor severity:
High
(NVD severity:Medium
).The vulnerability can be remediated by updating the library to version
2.6.7
or higher."Thanks!
The text was updated successfully, but these errors were encountered: