Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

async portscanner vulnerability 2.1.1 #1959

Closed
webdevelopland opened this issue Apr 28, 2022 · 5 comments
Closed

async portscanner vulnerability 2.1.1 #1959

webdevelopland opened this issue Apr 28, 2022 · 5 comments

Comments

@webdevelopland
Copy link

webdevelopland commented Apr 28, 2022

Hello, there's a vulnerability related to old version of async:
GHSA-fwr7-v2mv-hh25
image

browser-sync uses portscanner, which uses async.
Latest version of portscanner (2.2.0) already updated async and the issue fixed.
But browser-sync 2.27.9 still uses portscanner 2.1.1
https://github.com/BrowserSync/browser-sync/blob/master/packages/browser-sync/package.json#L56
image

Could you please update portscanner up to the latest version?

@suhailkc
Copy link

suhailkc commented May 2, 2022

I have the same issue.
Please update to portscanner@2.2.0

@kemenydani
Copy link

Agree, please upgrade.

@JackHowa
Copy link

JackHowa commented May 10, 2022

@shakyShane are you available to review this? really appreciate your work on this project! I know fixing small things in OSS can be annoying; thanks for your time! #1960

@shakyShane
Copy link
Contributor

Yep, I'll get to this tomorrow :)

@shakyShane
Copy link
Contributor

fixed in browser-sync@2.27.10 - thank you :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants