Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Hawk update to fix node security issues. #2456

Closed
wants to merge 3 commits into from

Conversation

Abhinay077
Copy link

No description provided.

@joepie91
Copy link

Assuming that this PR refers to this security advisory, it would not be necessary - the issue was resolved in version 3.1.3, which is the minimum version that request already requires.

Or is this meant to fix a different vulnerability?

@ilkka
Copy link

ilkka commented Jan 5, 2017

I think this might also fix a problem reported by auditjs: Request 2.79.0 -> Hawk 3.1.3 -> sntp 1.0.9 and that version of sntp is (according to auditjs) vulnerable to rosetta flash.

@FredKSchott
Copy link
Contributor

This should be okay to merge now that we've dropped 0.x support, any objections?
Fixes #2338 & #2436.

@ashawley
Copy link

Fixed in #2751 and released in 2.82.0.

@simov simov closed this May 17, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

6 participants