Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump up socks version to mitigate vulnerability in IP package #295

Closed
rovindra opened this issue Feb 23, 2024 · 7 comments
Closed

Bump up socks version to mitigate vulnerability in IP package #295

rovindra opened this issue Feb 23, 2024 · 7 comments

Comments

@rovindra
Copy link

https://github.com/TooTallNate/proxy-agents/blob/b5f94e3222c0aaa3bc56218ff125e2c56417c86e/packages/socks-proxy-agent/package.json#L112C17-L112C21

Socks has released the new version and removed the ip package because of having a vulnerability mentioned here: GHSA-78xj-cgh5-2h22

@elkinjosetm
Copy link

Any update on this?

@SpencerKaiser
Copy link

Just ran into this issue as well ☹️ it's been over a month - can we please get a patch for this??

@Ch1g
Copy link

Ch1g commented Mar 25, 2024

Would like to see this too!
If any help is needed, I'm willing to try

@hsol
Copy link

hsol commented Mar 27, 2024

We are awaiting resolution of this issue too. I understand it may be a low priority. Just please don't forget #297

@lukekarrys
Copy link
Collaborator

#297 has a few issues that need to be fixed before it can be merged.

That being said, #297 is only required to clear the vuln for local development of these packages. socks-proxy-agent depends on a range of socks which contains the fix, so all that is required for other projects is updating your transient deps.

@jonamenk
Copy link

jonamenk commented Jun 5, 2024

pac-proxy-agent was also not updated to latest [email protected] fixing the ip vulnerability.

Any plans to update these dependencies?

@TooTallNate
Copy link
Owner

#322

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

8 participants