feat: patch 4.2.0 with fixes for CVE-2020-8116 #61
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Because v5 drops support for Node < 8, I'm proposing this patch to bring the logic implemented to patch CVE-2020-8116, down to 4.2.0, in order for projects that are yet unable to drop support for Node < 8 to also patch the vulnerability.
This shouldn't be merged into master, but could potentially be published off of a v4.2.1 tag or separate branch. Let me know if I'm missing another way, or if this isn't something that would be helpful.