There is a vulnerability in node-forge 0.7.5,upgrade recommended
Open
- Dominant language
- JavaScript
- Stars
- 193
- Forks
- 112
- PR merge metrics
- No merged PRs in 30d
Description
https://github.com/Autodesk/hig/blob/80680833679c324da5bb36cfe74f36c15c9672bc/acceptance/yarn.lock#L7188-L7190
CVE-2020-7720
Recommended upgrade version:0.10.0
Contributor guide
Research direction
Inspect acceptance/yarn.lock at lines 7188-7190, where node-forge 0.7.5 is recorded. Update the dependency to 0.10.0 and verify the lockfile no longer pins the vulnerable version associated with CVE-2020-7720.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 55/100