Skip to content
This repository has been archived by the owner on Jan 21, 2024. It is now read-only.

Bug: update ajv dependency #91

Open
kavinho opened this issue Apr 6, 2021 · 1 comment · May be fixed by #95
Open

Bug: update ajv dependency #91

kavinho opened this issue Apr 6, 2021 · 1 comment · May be fixed by #95

Comments

@kavinho
Copy link

kavinho commented Apr 6, 2021

Library version used
"0.5.0"

Language library used with
JavaScript

Describe the bug
This lib depends on ajv:6.5.2 , which is vulnerable prototype pollution attack.
https://sca.analysiscenter.veracode.com/vulnerability-database/security/prototype-pollution/javascript/sid-25893

Expected behaviour/output
Can we update the dependency to 6.12.3 or later.

@0xvbetsun 0xvbetsun linked a pull request Dec 7, 2021 that will close this issue
@railsstudent
Copy link

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants