Upgrade tough-cookie to a version without regex DoS vulnerability#226
Upgrade tough-cookie to a version without regex DoS vulnerability#226analog-nico merged 1 commit intorequest:masterfrom
Conversation
|
Thanks for the quick fix! ❤️ |
|
@analog-nico The builds on Travis for node |
|
@willmorgan because the I think it may take a little while for the NSP advisory to be updated. |
|
Thanks a lot @rouanw ! I just published FYI, the build didn’t work because |
tough-cookieversion <=2.3.2 is currently vulnerable to a regex denial of service attack. See https://nodesecurity.io/advisories/525.This issue has been fixed in
tough-cookiev2.3.3. See salesforce/tough-cookie#92.