Skip to content
This repository has been archived by the owner on Aug 2, 2022. It is now read-only.

Fix vulnerability related to old node fetch #333

Closed
yizheliu-amazon opened this issue Nov 25, 2020 · 0 comments
Closed

Fix vulnerability related to old node fetch #333

yizheliu-amazon opened this issue Nov 25, 2020 · 0 comments

Comments

@yizheliu-amazon
Copy link
Contributor

https://github.com/opendistro-for-elasticsearch/anomaly-detection-kibana-plugin/network/alert/yarn.lock/node-fetch/open

 Dependabot cannot update node-fetch to a non-vulnerable version
The latest possible version that can be installed is 1.7.3 because of the following conflicting dependency:

formik@1.5.8 requires node-fetch@^1.0.1 via a transitive dependency on isomorphic-fetch@2.2.1
The earliest fixed version is 2.6.1.
yizheliu-amazon added a commit to yizheliu-amazon/anomaly-detection-kibana-plugin that referenced this issue Nov 25, 2020
@yizheliu-amazon yizheliu-amazon changed the title upgrade node fetch to 2.6.1 or above Fix vulnerability related to old node fetch Nov 25, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant