Addressing node-forge vulnerabilities #19636
Answered
by
yajatkaul
ste-curran
asked this question in
Help
Replies: 1 comment 1 reply
-
|
Beta Was this translation helpful? Give feedback.
1 reply
Answer selected by
ste-curran
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hi,
I am proposing to resolve CVEs GHSA-554w-wpv2-vw27 and GHSA-5gfm-wpxj-wjgq which relate to node-forge, a transitive dependency of listhen.
I could resolve the node-forge vulnerabilities by using an override of that dependency as there is no newer version of listhen. But I have two questions:
1 - Do vulnerabilities relating to a transitive dependency of listhen need to be updated? listhen is only used for testing.
2 - Would an override of node-forge be acceptable as a resolution approach if update is necessary?
Thanks!
Beta Was this translation helpful? Give feedback.
All reactions