-
Notifications
You must be signed in to change notification settings - Fork 21
Closed
Labels
priority: p2Moderately-important priority. Fix may not be included in next release.Moderately-important priority. Fix may not be included in next release.type: bugError or flaw in code with unintended results or allowing sub-optimal usage patterns.Error or flaw in code with unintended results or allowing sub-optimal usage patterns.
Description
Current version 3.5.2 published on NPM is vulnerable to CVE-2019-10790 GHSA-mxhp-79qh-mcx6
MEND Renovate patched the affected dependencies last week, but there was no 3.5.3 released.
-
Is this a client library issue or a product issue?
Client library: library failsnpm audit -
Did someone already solve this?
MEND Renovate already did the first part in fix(deps): update dependency protobufjs to v7.2.1 gax-nodejs#1411 & fix(deps): update dependency protobufjs-cli to v1.1.0 gax-nodejs#1412
But the changes were never released -
Do you have a support contract?
Nope
Environment details
- OS: WSL Debian Bookwork
- Node.js version: 18.13.0
- npm version: 8.19.3
google-gaxversion: 3.5.2
Steps to reproduce
npm i google-gaxnpm audit
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
priority: p2Moderately-important priority. Fix may not be included in next release.Moderately-important priority. Fix may not be included in next release.type: bugError or flaw in code with unintended results or allowing sub-optimal usage patterns.Error or flaw in code with unintended results or allowing sub-optimal usage patterns.