-
Notifications
You must be signed in to change notification settings - Fork 246
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump up socks version to mitigate vulnerability in IP package #295
Comments
Any update on this? |
Just ran into this issue as well |
Would like to see this too! |
We are awaiting resolution of this issue too. I understand it may be a low priority. Just please don't forget #297 |
#297 has a few issues that need to be fixed before it can be merged. That being said, #297 is only required to clear the vuln for local development of these packages. |
Any plans to update these dependencies? |
https://github.com/TooTallNate/proxy-agents/blob/b5f94e3222c0aaa3bc56218ff125e2c56417c86e/packages/socks-proxy-agent/package.json#L112C17-L112C21
Socks has released the new version and removed the ip package because of having a vulnerability mentioned here: GHSA-78xj-cgh5-2h22
The text was updated successfully, but these errors were encountered: