Skip to content

[email protected] deprecated and embeds vulnerability  #115

@boly38

Description

@boly38

Hi
thanks for this lib!

it seems that right now, [email protected] (source) is deprecated and embeds vulnerability

└─┬ [email protected]
  └─┬ [email protected]
    └─┬ [email protected]
      └── [email protected]

request  *
Severity: moderate
Server-Side Request Forgery in Request - https://github.com/advisories/GHSA-p8p7-x288-28g6
Depends on vulnerable versions of tough-cookie
No fix available
node_modules/request
  phantomjs-prebuilt  *
  Depends on vulnerable versions of request
  node_modules/phantomjs-prebuilt
    html-pdf  >=2.0.0
    Depends on vulnerable versions of phantomjs-prebuilt
    node_modules/html-pdf
      pdf-creator-node  *
      Depends on vulnerable versions of html-pdf
      node_modules/pdf-creator-node

as html-pdf is deprecated, there is a tips on npmjs page to move to puppeteer.

IDK really the impact :) but did you plan to migrate dep in order to fix the request moderate vulnerability ?

Thanks

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions