Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update got to latest please #68

Open
tomcon opened this issue Jul 14, 2022 · 2 comments
Open

Update got to latest please #68

tomcon opened this issue Jul 14, 2022 · 2 comments

Comments

@tomcon
Copy link

tomcon commented Jul 14, 2022

npm audit report

got <11.8.5
Severity: moderate
Got allows a redirect to a UNIX socket - GHSA-pfrx-2q88-qq97
No fix available
node_modules/@shelf/tika-text-extract/node_modules/got
@shelf/tika-text-extract *
Depends on vulnerable versions of got
node_modules/@shelf/tika-text-extract

@vladholubiev
Copy link
Member

PRs are welcome

But I don't think this issue is relevant to this package

This package doesn't allow a user-provided URL

It always calls localhost:9998 and it cannot be changed outside of the package by a library user

@GTCrais
Copy link

GTCrais commented Jun 11, 2024

@vladholubiev this this is true, in our particular case, we need to be SOC2 compliant, and got 11.8.6 is flagged as a vulnerability, regardless of how inconsequential it is.

I'm trying to get the next minimum acceptable version to work (v12.1.0), but I'm having issues with this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

3 participants