Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update node-fetch to v3.x #200

Open
jimmywarting opened this issue Nov 8, 2021 · 7 comments
Open

update node-fetch to v3.x #200

jimmywarting opened this issue Nov 8, 2021 · 7 comments

Comments

@jimmywarting
Copy link

No description provided.

@cosmolightfoot
Copy link

Any progress on this one?

Our company's security scans are showing vulnerabilities in node-fetch and are blocking deploys based on this package based on the sub-dependency.
node-fetch v3.1.1 solves the issue.

@borisovg
Copy link

Apparently node-fetch v3 breaks non-ESM applications: node-fetch/node-fetch#1263

@bhavikagrawal
Copy link

bhavikagrawal commented Feb 2, 2022

I am also stuck for a week now and have not found any solution yet.

@jimmywarting
Copy link
Author

@bhavikagrawal what are you stuck with?
anything i can do to help?

@RishikeshDarandale
Copy link

@jimmywarting , I am also stuck in one of the issue, the fix for this one is get updated to node-fetch - v3.x.

@shazron
Copy link

shazron commented Feb 7, 2022

2.6.7 also has the security patch

@RishikeshDarandale
Copy link

@shazron , Yes it's patched in 2.6.7, but there is an issue using 2.x in tandem with auth-react package. Please see here, thus upgrade 3.x would be the best way for me. Yes, there is a workaround using with 2.x, but going with 3.x is better way for me.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants