Skip to content

Conversation

@k725
Copy link
Contributor

@k725 k725 commented Oct 7, 2024

The kind of change this PR does introduce

  • a bug fix
  • a new feature
  • an update to the documentation
  • a code change that improves performance
  • other

Current behavior

An existing dependency "cookie" has a vulnerability.

New behavior

  • "cookie" has been updated to a version that fixes the vulnerability.
  • The contents of the package-lock.json seem to have been inconsistent (see diff). I ran npm i to correct it.

close #5206

Other information (e.g. related issues)

GHSA-pxg6-pf52-xh8x
https://avd.aquasec.com/nvd/2024/cve-2024-47764/
https://security.snyk.io/vuln/SNYK-JS-COOKIE-8163060

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

vuln: cookie package

2 participants