Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot alert: mpath < 0.8.4 #54

Closed
rpenido opened this issue Sep 10, 2021 · 4 comments
Closed

Dependabot alert: mpath < 0.8.4 #54

rpenido opened this issue Sep 10, 2021 · 4 comments

Comments

@rpenido
Copy link

rpenido commented Sep 10, 2021

Issue solved in mongoose: Automattic/mongoose#10683

@vkarpov15
Copy link
Member

This should be fixed with Mongoose v5.13.9, so we can close this issue for now.

@vkarpov15
Copy link
Member

Also, just to confirm, the security issue in mpath <= 0.8.3 does not impact mongoose.

@rpenido
Copy link
Author

rpenido commented Sep 15, 2021

This should be fixed with Mongoose v5.13.9, so we can close this issue for now.

I don't understand. This plugin is not necessary with mongoose v5.13.9?

@vkarpov15 vkarpov15 reopened this Sep 18, 2021
@vkarpov15
Copy link
Member

That's our mistake, we didn't realize that this project depended on mpath directly.

We can confirm that the security issue in mpath <= 0.8.3 does not affect this project.

We fixed this in d116890 and released v0.8.1 👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants