This repository was archived by the owner on Sep 3, 2022. It is now read-only.
This repository was archived by the owner on Sep 3, 2022. It is now read-only.
Vulnerable is-email dependency in 4.1.11 #260
Open
Description
I have "@segment/analytics.js-core": "4.1.11",
installed.
When running npm audit
I get the following error:
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Improper Input Validation in is-email │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ is-email │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=1.0.1 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ @segment/analytics.js-core │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ @segment/analytics.js-core > segmentio-facade > is-email │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-j377-2x76-558h │
└───────────────┴──────────────────────────────────────────────────────────────┘
I understand that there is a fix for is-email, but since segmentio-facade
depends on the exact version 0.1.0 I'm not sure if it is compatible.
Can you update the dependencies for segmentio-facade and @segment/analytics.js-core that they don't use is-email 0.1.0?
Metadata
Metadata
Assignees
Labels
No labels