Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security] ws package vulnerability through puppeteer@14 #665

Open
anfern777 opened this issue Aug 12, 2024 · 3 comments
Open

[Security] ws package vulnerability through puppeteer@14 #665

anfern777 opened this issue Aug 12, 2024 · 3 comments
Labels

Comments

@anfern777
Copy link

Description
"[email protected]" package has known vulnerabilities and is present in dependency tree through puppeter:^14.1.0

Details
The ws package, has known vulnerabilities, is being included as a transitive dependency: GHSA-3h5v-q93c-6h6q
Below is the detailed dependency chain:

html-template@2.3.10
├── puppeteer@ ^14.1.0
    └── ws: 8.6.0 
Copy link

Welcome to AsyncAPI. Thanks a lot for reporting your first issue. Please check out our contributors guide and the instructions about a basic recommended setup useful for opening a pull request.
Keep in mind there are also other channels you can use to interact with AsyncAPI community. For more details check out this issue.

Copy link
Member

derberg commented Aug 20, 2024

affects only users that use pdf generation flag

Copy link

This issue has been automatically marked as stale because it has not had recent activity 😴

It will be closed in 120 days if no further activity occurs. To unstale this issue, add a comment with a detailed explanation.

There can be many reasons why some specific issue has no activity. The most probable cause is lack of time, not lack of interest. AsyncAPI Initiative is a Linux Foundation project not owned by a single for-profit company. It is a community-driven initiative ruled under open governance model.

Let us figure out together how to push this issue forward. Connect with us through one of many communication channels we established here.

Thank you for your patience ❤️

@github-actions github-actions bot added the stale label Dec 19, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants