-
Notifications
You must be signed in to change notification settings - Fork 1.3k
Security vulnerability [CVE-2021-3918] #3204
Comments
thanks for the issue. I believe If the aforementioned |
Moving away from request is an option already implemented in node-gyp v8 here - i.e. the clearest success path for node-sass to me looks like upgrading node-gyp from v7 plus any direct usages here in node-sass (as it is also in dependencies at the moment). However, another option is suggested here too, so it's possible it might get resolved upstream too. |
It also looks like others would like to move away from requests: #3200 |
is this project still being actively maintained? |
Anyone still looking into this issue? I am also facing the same issue. Latest version of json-schema (0.4.0) is available which has some vulnerability fixes but due to node-sass dependency couldn't upgrade. |
is it viable to uninstall |
for what it's worth, I replaced
|
|
yup @pzrq, I already took care of it and it was a breeze :) |
Should be resolved when #3209 is released. |
Fixed in 7.0.1. |
Dependency tree:
[email protected] > [email protected] > [email protected] > [email protected] > [email protected] > [email protected]
CVE-2021-3918
I guess it's present
[email protected]
and[email protected]
as well.The text was updated successfully, but these errors were encountered: