CVE-2022-38900 fix for npm v6 - #6010
c3ivodujmovic wants to merge 41 commits into
Conversation
|
@wraithgar @ruyadorno what do you guys recommend is the best way to address this issue? |
|
the npm team will audit the vulnerability and create a release for v6 if necessary. currently v6 is only being released with urgent security fixes. |
|
Thanks @lukekarrys . Tell me if there is anything I can help. Background |
|
There is an open PR to land this change in node 14 which can be followed to track the progress there: nodejs/node#45936 |
query-string@7.1.3 see GHSA-5698-6q73-gp8h