-
Notifications
You must be signed in to change notification settings - Fork 1.8k
Update archiver to 7.0.0 to avoid CVE-772 in inflight @ 1.0.6 #2715
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
I am also running into this issue, hopefully it gets fixed soon! |
Gentle bump 🙃 |
Any fix? |
The vulnerable references to
|
Try #2829 (comment) |
Following this topic 👀 |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
🚀 Feature Proposal
Current version of
exceljs
referencesarchiver
of v5.3.2. In the references, you can find the inflight package that is affected by CVE-772 ( https://security.snyk.io/vuln/SNYK-JS-INFLIGHT-6095116 )exceljs @ 4.4.0 -> archiver @ 5.3.2 -> archiver-utils @ 2.1.0 -> glob @ 7.2.3 -> inflight @ 1.0.6
The
archiver
andarchiver-utils
packages were already updated and published on npm.Please update the
archiver
package reference inexceljs
to 7.0.0 to avoid the vulnerabilityNote that this may result in a breaking change as support of Node 12 has been dropped: archiverjs/node-archiver#735
The text was updated successfully, but these errors were encountered: