Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: bump https-proxy-agent to mitigate a security issue #5016

Merged
merged 1 commit into from Oct 10, 2019
Merged

chore: bump https-proxy-agent to mitigate a security issue #5016

merged 1 commit into from Oct 10, 2019

Conversation

kachkaev
Copy link
Contributor

@kachkaev kachkaev commented Oct 7, 2019

Context:

According to release notes, the bump should not bring any breaking changes for Puppeteer. I believe it can get shipped with the next patch release.

@googlebot
Copy link

Thanks for your pull request. It looks like this may be your first contribution to a Google open source project (if not, look below for help). Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

📝 Please visit https://cla.developers.google.com/ to sign.

Once you've signed (or fixed any issues), please reply here with @googlebot I signed it! and we'll verify it.


What to do if you already signed the CLA

Individual signers
Corporate signers

ℹ️ Googlers: Go here for more info.

@kachkaev
Copy link
Contributor Author

kachkaev commented Oct 7, 2019

@googlebot I signed it!

@googlebot
Copy link

CLAs look good, thanks!

ℹ️ Googlers: Go here for more info.

Copy link

@bmeurer bmeurer left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks.

@mastermatt
Copy link

@mathiasbynens I'm not sure what the release schedule is for this lib, but could we get a patch for this?

@kachkaev
Copy link
Contributor Author

Also can't wait for a patch release to stop seeing security warnings in Snyk. Some of my projects depend on puppeteer, which brings in vulnerable https-proxy-agent@2.2.2.

🙏

@mastermatt
Copy link

@bmeurer and @mathiasbynens it looks like dropping Node v6 support was merged to master since this went in. Will that require a major version bump of puppeteer?
Can I please request that a simple patch version of 1.20 be released with this security vulnerability fixed first?

@warpech
Copy link

warpech commented Oct 23, 2019

Fixes #5055

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

6 participants