Giter VIP home page Giter VIP logo

Comments (6)

parithibang avatar parithibang commented on May 28, 2024 1

@rwlodarczyk-xealth @lquixada
May I know the update on this ticket as we are consuming this package and this is blocked for security issue.

Ref:
https://huntr.dev/bounties/a7e6a136-0a4b-46c4-ad20-802f1dd60bf7/
https://huntr.dev/bounties/d26ab655-38d6-48b3-be15-f9ad6b6ae6f7/

from cross-fetch.

sokraflex avatar sokraflex commented on May 28, 2024

We're using cross-fetch in many internal libraries, and #117 is critical; currently, many of our libraries are failing due to missing DNS caching when using node-fetch.

from cross-fetch.

rwlodarczyk-xealth avatar rwlodarczyk-xealth commented on May 28, 2024

We have the same concerns here. If this package updates itself to use node-fetch 3.2.10, that would be tremendously helpful. Please see the CVE that discusses the security issue.

from cross-fetch.

rwlodarczyk-xealth avatar rwlodarczyk-xealth commented on May 28, 2024

@lquixada, can you provide an update on this and fixing security issues in general?

from cross-fetch.

rwlodarczyk-xealth avatar rwlodarczyk-xealth commented on May 28, 2024

@lquixada Friendly reminder about this security issue. Any update?

from cross-fetch.

lquixada avatar lquixada commented on May 28, 2024

Starting from v3, node-fetch is an ESM-only module while cross-fetch is CommonJS compatible. If there's a security issue, a patch should be requested on node-fetch v2.x. FWIW [email protected] was recently released with [email protected].

from cross-fetch.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.