-
Notifications
You must be signed in to change notification settings - Fork 1.6k
Open
Description
form-data <2.5.4
Severity: critical
form-data uses unsafe random function in form-data for choosing boundary - https://github.com/advisories/GHSA-fjxv-7rqg-78g4
fix available via `npm audit fix --force`
Will install node-telegram-bot-api@0.63.0, which is a breaking change
node_modules/request/node_modules/form-data
request *
Depends on vulnerable versions of form-data
Depends on vulnerable versions of tough-cookie
node_modules/request
request-promise-core *
Depends on vulnerable versions of request
node_modules/request-promise-core
@cypress/request-promise *
Depends on vulnerable versions of request-promise-core
node_modules/@cypress/request-promise
node-telegram-bot-api >=0.64.0
Depends on vulnerable versions of @cypress/request-promise
node_modules/node-telegram-bot-api
Metadata
Metadata
Assignees
Labels
No labels