Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: upgrade [email protected] #286

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

billfeller
Copy link

@billfeller billfeller commented Jan 25, 2022

升级 isomorphic-fetch 版本为 3.0.0 将 node-fetch 依赖版本升级为 2.6.7 ,修复 node-fetch (< 2.6.7) 漏洞 CVE-2022-0235
http://horus.oa.com/advisory/HOSA-h0oi-ipysan7q4

@sorrycc

@magicdawn
Copy link

ping status ?

AND should fix #225

@yinyanfr
Copy link

Anyone please review and merge this.

@skitsanos
Copy link

maybe we should have more people with merge rights here?... snyk still reporting the issue... i don't know even if need node-fetch at all lately with fetch introduced natively... maybe there is a need for refactored umi-request that targets 'everything new' ?...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants