Git Product home page Git Product logo

Comments (6)

Jiralite avatar Jiralite commented on September 24, 2024 1

https://github.com/nodejs/undici/releases/tag/v6.6.1 is the security release. We are already updated: ae57d7f

There's nothing to do other than make a release, which will come naturally.

from discord.js.

Syjalo avatar Syjalo commented on September 24, 2024 1

It's closed as not planned, because there's nothing to fix. It's invalid, because it reports a bug that doesn't exist.
image

from discord.js.

techy2493 avatar techy2493 commented on September 24, 2024

If this is fixed why was it closed as not planned and tagged as invalid instead of being marked as something resolved in an upcoming release @Jiralite which would let others know it was resolved?

from discord.js.

JstnMcBrd avatar JstnMcBrd commented on September 24, 2024

I am also receiving this dependabot alert. I eagerly await the next release with this bug fix.

Is it possible to release an expedited patch (14.14.2) that fixes this problem quickly? Or is bumping undici's version a breaking change that requires a minor/major release?

from discord.js.

monbrey avatar monbrey commented on September 24, 2024

There's no need to expedite a patch for this. You can safely ignore it. We are not impacted by this CVE as we are not making cross-origin requests (as far as I know)

from discord.js.

YasharF avatar YasharF commented on September 24, 2024

Per GHSA-3787-6prv-h9w3 it is patched in undici v6.6.1
@discordjs/rest has picked up the patch in ae57d7f

from discord.js.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.