-
Notifications
You must be signed in to change notification settings - Fork 75
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
NPM audit failing due to vulnerability in ip
dependency
#620
Comments
This is the CVE: https://nvd.nist.gov/vuln/detail/CVE-2024-29415 |
Hi. Thanks for the report. There's no current workaround here. No patch has yet been released for |
Also notable: indutny/node-ip#150 (comment) |
@chriswk |
Fixes Unleash#620 Replacing `ip` pacakage for `ip-address` package to address https://nvd.nist.gov/vuln/detail/CVE-2024-29415.
* feat: replacing ip package for ip-address package Fixes #620 Replacing `ip` package for `ip-address` package to address https://nvd.nist.gov/vuln/detail/CVE-2024-29415.
Please release this as soon as possible, as it resolves auditing issues. |
Describe the bug
Since yesterday, the NPM audit of my application (which uses unleash-client) has been failing due to what looks to be a vulnerability in the
ip
dependency:It looks like the dependency will need updating.
Steps to reproduce the bug
No response
Expected behavior
No response
Logs, error output, etc.
No response
Screenshots
No response
Additional context
No response
Unleash version
No response
Subscription type
None
Hosting type
None
SDK information (language and version)
No response
The text was updated successfully, but these errors were encountered: