-
Notifications
You must be signed in to change notification settings - Fork 1.2k
Description
Hello,
yarn audit show this output jose dependency is vulnerable is it possible to upgrade or replace it ?
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ moderate │ jose vulnerable to resource exhaustion via specifically │
│ │ crafted JWE with compressed plaintext │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ jose │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=4.15.5 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ newman │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ newman > postman-runtime > jose │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://www.npmjs.com/advisories/1096835