-
Notifications
You must be signed in to change notification settings - Fork 101
Open
Description
There are some CVE findings from npm audit --omit dev. To improve the confidence of those who use retry, we can update them with npm audit fix.
Findings:
❯ npm audit --omit dev
# npm audit report
undici <=5.28.5
Severity: moderate
Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect - https://github.com/advisories/GHSA-9qxr-qj54-h672
Undici proxy-authorization header not cleared on cross-origin redirect in fetch - https://github.com/advisories/GHSA-3787-6prv-h9w3
Use of Insufficiently Random Values in undici - https://github.com/advisories/GHSA-c76h-2ccp-4975
Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline - https://github.com/advisories/GHSA-m4v8-wqvr-p9f7
undici Denial of Service attack via bad certificate data - https://github.com/advisories/GHSA-cxrh-j4jr-qwg3
fix available via `npm audit fix`
node_modules/undici
1 moderate severity vulnerability
To address all issues, run:
npm audit fix
Metadata
Metadata
Assignees
Labels
No labels