Skip to content
This repository has been archived by the owner on Jan 9, 2023. It is now read-only.

Fix vulnerability CVE-2018-3728 #53

Merged

Conversation

armstnp
Copy link
Contributor

@armstnp armstnp commented Apr 27, 2018

Bumping request 2.54.0 dependency to the latest stable version request 2.85.0. This bumps its vulnerable descendant dependency hoek to a patched version that covers the CVE.

While the CVE recommended path is to use hoek 5.0.3, but the issue is stated to have been confirmed fixed in hoek 4.2.1, which is what the request 2.85.0 package uses. See: request#2926

@coveralls
Copy link

coveralls commented Apr 27, 2018

Coverage Status

Coverage remained the same at 87.862% when pulling 670b11b on armstnp:fix/vuln-CVE-2018-3728 into 75ee1bd on smartsheet-platform:master.

Copy link
Contributor

@cameronbowie cameronbowie left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good

@cameronbowie cameronbowie merged commit d7dce22 into smartsheet-platform:master May 2, 2018
@armstnp armstnp deleted the fix/vuln-CVE-2018-3728 branch May 2, 2018 17:38
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants