-
Notifications
You must be signed in to change notification settings - Fork 641
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Dependency url-signature using a version of crypto-js with critical vulnerability #1104
Comments
If you would like to upvote the priority of this issue, please comment below or react on the original post above with 👍 so we can see what is popular when we triage.@elrond30 Thank you for opening this issue. 🙏
This is an automated message, feel free to ignore. |
v1.0.30 of js-url-signature has been released with the updated dependency. We'll need to update the dependency in this library to pull that in. |
@usefulthink after you merge #1046, could you update this dependency? Causing a CVE. |
Since the dependency range in the current package.json includes minor and patch releases of js-url-signature at or above v1.0.4, this library now will pull in v1.0.30 without any changes required (may require an |
Fixed by #1110 |
Thank you for the fix |
Hi, looks like the package.json is using url-signature 1.0.4, which use a version of crypto-js with critical vulnerability. There is an opened issue in js-url-signature with a Pull Request, to update crypto-js version and solve the vulnerability.
googlemaps/js-url-signature#446
Thanks.
The text was updated successfully, but these errors were encountered: