Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update cookie to 0.7.2 #5205

Merged
merged 1 commit into from
Oct 9, 2024
Merged

Conversation

k725
Copy link
Contributor

@k725 k725 commented Oct 7, 2024

The kind of change this PR does introduce

  • a bug fix
  • a new feature
  • an update to the documentation
  • a code change that improves performance
  • other

Current behavior

An existing dependency "cookie" has a vulnerability.

New behavior

  • "cookie" has been updated to a version that fixes the vulnerability.
  • The contents of the package-lock.json seem to have been inconsistent (see diff). I ran npm i to correct it.

close #5206

Other information (e.g. related issues)

GHSA-pxg6-pf52-xh8x
https://avd.aquasec.com/nvd/2024/cve-2024-47764/
https://security.snyk.io/vuln/SNYK-JS-COOKIE-8163060

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

vuln: cookie package
2 participants