-
Notifications
You must be signed in to change notification settings - Fork 2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
@uppy/companion 0.16.0 depends on morgan 1.9.0 which introduces a moderate code injection vulnerability #1227
Labels
Companion
The auth server (for Instagram, GDrive, etc) and upload proxy (for S3)
Comments
Fixing in #1232, thanks for the report! |
goto-bus-stop
added a commit
that referenced
this issue
Jan 7, 2019
companion: Update morgan dependency, fixes #1227
This was referenced Dec 30, 2020
This was referenced Dec 10, 2021
This was referenced Aug 11, 2022
HeavenFox
pushed a commit
to docsend/uppy
that referenced
this issue
Jun 27, 2023
This was referenced May 7, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
The following is the output form
npm audit
after installing@uppy/companion
at 0.16.0:The text was updated successfully, but these errors were encountered: