ember-cli / ember-cli/ember-fetch

Upgrade package "node-fetch" to fix

Open
#730 0 comments 1 reaction 0 assignees View on GitHub
Dominant language
JavaScript
Stars
176
Forks
78
PR merge metrics
No merged PRs in 30d

Description

https://github.com/advisories/GHSA-r683-j2x4-v87g suggests to us 2.6.7 or above to fix vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Ember-fetch is on 2.6.1
https://github.com/ember-cli/ember-fetch/blob/master/package.json#L40

In order to fix the CVE the dependency should be upgraded.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.