Skip to content

Security issues within make-fetch-happen #779

@Johannesklint

Description

@Johannesklint

Describe the bug

The dependency chain is quite large but basically cross-spawn has a known security issue in the version used in this project. I think that it'll be enough for you to bump make-fetch-happen to the latest version and you'll be good

Here is the chain all the way down to cross-spawn

unleash-client@6.6.0
  → make-fetch-happen@13.0.1
    → cacache@18.0.4
      → glob@10.4.5
        → foreground-child@3.3.0
          → cross-spawn@7.0.3

Metadata

Metadata

Labels

Type

No type

Projects

Status

Investigating

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions