Uh oh!
There was an error while loading. Please reload this page.
Require debug ^2.6.9 - #17
Conversation
There is a minor security vulnerability in the module `debug`: https://nodesecurity.io/advisories/534 This was resolved in 2.6.9 and 3.1.0. Debug introduced let/const in v3.2.0, breaking compatibility with node.js v4 and older browsers. This was reverted in 3.2.4, then re-released it in 4.0.0 - see debug-js/debug#603 for context around that. In order avoid the vulnerability without loosing any compatibility, this change locks component-cookie to >= 3.2.4 < 4.0.0. Version `^2.6.9` could alternatively be used if desired. This Fixescomponent#16, Fixescomponent#15, and is is part of the fix for matthewmueller/next-cookies#7
based on feedback from @f2prateek
jescalan
commented
Nov 26, 2018
This is pretty important to get merged and upgraded. This package currently exposes a security vulnerability. Is this package still maintained? |
jescalan
commented
Nov 26, 2018
cc @ucarion |
BTW, I just locked next-cookies to |
|
jescalan
commented
Dec 19, 2018
This package does not use |
You should be able to upgrade safely, FWIW. The OP was written during one of the first upgrades in over a year, and the subsequent patch fixes. |
RajaBellebon
commented
Mar 17, 2020
Hello, what is the status on this PR? We are also facing some vulnerabilities issues bc of Thank you |
nfriedly
commented
Mar 17, 2020
This PR is still waiting on acceptance, as is my other bug fix, #19. For next-cookies, I ended up switching to universal-cookie. |
Tenaria
commented
Apr 6, 2021
Hi, is there any update on this? Similarly to the other comments, we are facing vulnerability issues with this as well and was wondering if there will be any movement on this soon 😄 |
cc @ucarion 🥺 |
ucarion
commented
Apr 14, 2021
Hi all -- it's been a few years since I've last published this package, but I am going to attempt to merge this PR and cut a new release. |
ucarion
commented
Apr 14, 2021
I believe this PR is now released as part of v1.1.5. |
There is a minor security vulnerability in the module
debug: https://nodesecurity.io/advisories/534This was resolved in debug@2.6.9 and 3.1.0.
Debug introduced let/const in v3.2.0, breaking compatibility with node.js v4 and older browsers. This was reverted in 3.2.4, then re-released it in 4.0.0 - see debug-js/debug#603 for context around that.
In order avoid the vulnerability without loosing any compatibility, this change locks component-cookie to
(Update: now^3.2.4(>= 3.2.4 and < 4.0.0).^2.6.9)This Fixes#16, relates to #15, and is is part of the fix for matthewmueller/next-cookies#7