Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

qs module need to be update #3272

Closed
myvyang opened this issue Apr 7, 2017 · 3 comments
Closed

qs module need to be update #3272

myvyang opened this issue Apr 7, 2017 · 3 comments
Assignees

Comments

@myvyang
Copy link

myvyang commented Apr 7, 2017

see ljharb/qs#200

a DoS is there.

@dougwilson
Copy link
Contributor

We already updated to 6.4.0; there is no newer version of qs to upgrade to. You can confirm in the npm registry what version of qs the latest version of Express depends on:

$ npm info express dependencies.qs
6.4.0

@dougwilson
Copy link
Contributor

And here is a link to the Snyk report for the latest version of Express: https://snyk.io/test/npm/express

@dougwilson
Copy link
Contributor

In the future, please follow the security policies of the module you are making an issue against. The standard signal is to have a Security.md file in the repo, and here is ours: https://github.com/expressjs/express/blob/master/Security.md

When you open issues in GitHub repositories, GitHub will show a yellow banner that you need to read our Contributing.md before filing an issue (https://github.com/expressjs/express/blob/master/Contributing.md). In that document, it also says:

The only exception is security dislosures which should be sent privately.

@expressjs expressjs locked and limited conversation to collaborators Apr 7, 2017
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

2 participants