You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Title: Update the lockfile to automatically remove the vulnerability introduced in [email protected]
Hi, @ashevat, I have reported a vulnerability in package tedious.
Title: Update the lockfile to automatically remove the vulnerability introduced in [email protected]
Hi, @ashevat, I have reported a vulnerability in package tedious.
As far as I am aware, vulnerability CVE-2021-28458 detected in package @azure/ms-rest-nodeauth<3.0.8 is directly referenced by [email protected], on which your package [email protected] transiively depends. As such, this vulnerability can also affect [email protected] via the following path:
[email protected] ➔ [email protected] ➔ [email protected] ➔ @azure/[email protected](vulnerable version)
Since tedious has released a new patched version [email protected] to resolve this issue ([email protected] ➔ @azure/[email protected](fix version)), then this vulnerability patch can be automatically propagated into your project only if you update your lockfile. The following is your new dependency path :
[email protected] ➔ [email protected] ➔ [email protected] ➔ @azure/[email protected](vulnerability fix version)
.A warm tip.^_^
The text was updated successfully, but these errors were encountered: