ember-cli / ember-cli/ember-fetch
Upgrade package "node-fetch" to fix
Open
- Dominant language
- JavaScript
- Stars
- 176
- Forks
- 78
- PR merge metrics
- No merged PRs in 30d
Description
https://github.com/advisories/GHSA-r683-j2x4-v87g suggests to us 2.6.7 or above to fix vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Ember-fetch is on 2.6.1
https://github.com/ember-cli/ember-fetch/blob/master/package.json#L40
In order to fix the CVE the dependency should be upgraded.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.