Skip to content

[MAINT]: 20.x npm audit vulnerabilities #486

@benpbolton

Description

@benpbolton

Describe the need

A variety of reasons might require a project to not (yet) leverage main (21.x) due to the full conversion to ESM.

The 20.x branch is purportedly vulnerable to:

GHSA-2p57-rm9w-gvfp
GHSA-3xgq-45jj-v275
GHSA-67mh-4wv8-2f99
GHSA-78xj-cgh5-2h22
GHSA-952p-6rrq-rcjv
GHSA-9qxr-qj54-h672
GHSA-9wv6-86v2-598j
GHSA-c2qf-rxjj-qqgw
GHSA-c76h-2ccp-4975
GHSA-c7qv-q95q-8v27
GHSA-f5x3-32g6-xq36
GHSA-grv7-fg5c-xmjg
GHSA-h5c3-5r3r-rr8q
GHSA-m4v8-wqvr-p9f7
GHSA-m6fv-jmcg-4jfg
GHSA-pxg6-pf52-xh8x
GHSA-qwcr-r2fm-qrc7
GHSA-rhx6-c78j-4q9w
GHSA-rmvr-2pp2-xj38
GHSA-xx4v-prfh-6cgc

Image

SDK Version

No response

API Version

No response

Relevant log output

npm audit | egrep -oe "https://github.com/advisories/.*" | sort -u
https://github.com/advisories/GHSA-2p57-rm9w-gvfp
https://github.com/advisories/GHSA-3xgq-45jj-v275
https://github.com/advisories/GHSA-67mh-4wv8-2f99
https://github.com/advisories/GHSA-78xj-cgh5-2h22
https://github.com/advisories/GHSA-952p-6rrq-rcjv
https://github.com/advisories/GHSA-9qxr-qj54-h672
https://github.com/advisories/GHSA-9wv6-86v2-598j
https://github.com/advisories/GHSA-c2qf-rxjj-qqgw
https://github.com/advisories/GHSA-c76h-2ccp-4975
https://github.com/advisories/GHSA-c7qv-q95q-8v27
https://github.com/advisories/GHSA-f5x3-32g6-xq36
https://github.com/advisories/GHSA-grv7-fg5c-xmjg
https://github.com/advisories/GHSA-h5c3-5r3r-rr8q
https://github.com/advisories/GHSA-m4v8-wqvr-p9f7
https://github.com/advisories/GHSA-m6fv-jmcg-4jfg
https://github.com/advisories/GHSA-pxg6-pf52-xh8x
https://github.com/advisories/GHSA-qwcr-r2fm-qrc7
https://github.com/advisories/GHSA-rhx6-c78j-4q9w
https://github.com/advisories/GHSA-rmvr-2pp2-xj38
https://github.com/advisories/GHSA-xx4v-prfh-6cgc

> 31 vulnerabilities (3 low, 18 moderate, 10 high)

Code of Conduct

  • I agree to follow this project's Code of Conduct

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions