Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GitHub detected a vulnerability in the nanoid dependency #509

Closed
aaronenyeshi opened this issue Jan 24, 2022 · 1 comment
Closed

GitHub detected a vulnerability in the nanoid dependency #509

aaronenyeshi opened this issue Jan 24, 2022 · 1 comment
Assignees

Comments

@aaronenyeshi
Copy link
Member

There is a vulnerability ticket opened internally on pytorch/kineto, related to Tensorboard. Could someone please help take a look? @guotuofeng, @guyang3532 - are you guys the maintainers for tb_plugin? I couldn't find you internal.

GitHub has detected that a package defined in the tb_plugin/fe/yarn.lock file of the pytorch/kineto repository contains a security vulnerability.

Package name: nanoid
Affected versions: < 3.1.31
Fixed in version: 3.1.31
Severity: MODERATE

Identifier(s):
GHSA-qrpm-p2h7-hrv2
CVE-2021-23566

Reference(s):
https://nvd.nist.gov/vuln/detail/CVE-2021-23566
ai/nanoid#328
https://github.com/…/2b7bd9332bc49b6330c7ddb08e5c661833db25…
https://gist.github.com/ar…/bc6d1eb9a3477d15d2772e876169a444
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2332550
https://snyk.io/vuln/SNYK-JS-NANOID-2332193
GHSA-qrpm-p2h7-hrv2

This task should automatically close when the alert is cleared on GitHub.

@aaronenyeshi
Copy link
Member Author

Thanks for the fix @guotuofeng , closing this. And will re-open if any issues persist.

guotuofeng added a commit that referenced this issue Feb 16, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants