Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Latest released version (1.7.0) contains Axios CVE-2023-45857 #133

Open
jracabado opened this issue Jan 3, 2024 · 1 comment
Open

Latest released version (1.7.0) contains Axios CVE-2023-45857 #133

jracabado opened this issue Jan 3, 2024 · 1 comment

Comments

@jracabado
Copy link

The fix has already been merged in master (99b7eb0abff808ac9470a60a39c7f5e22c464b0f), could we get a new NPM release with this?

@SnowySailor
Copy link

Bumping this @yakovkhalinsky

Installing with npm install backblaze-b2 will install the version with the vulnerability. You will need to bump the version number to 1.7.1 and npm publish this package again for the vulnerability fix to be available for others.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants