Skip to content

Dependency selfsigned old, creates transitive dependency on vulnerable node-forge #5617

@benknoble

Description

@benknoble

Bug Description

There are newer versions of selfsigned available with updated (or even without!) node-forge. Please consider updating this package’s dependency so vulnerable node-forge versions don’t have to be overridden downstream.

Link to Minimal Reproduction and step to reproduce

You can easily see this by examining package-lock.json after installing the latest version of this package.

Expected Behavior

Vulnerable dependencies should be updated.

Actual Behavior

Vulnerable node-forge is installed.

Environment

macOS and linux; but it shouldn’t matter here.

Is this a regression?

None

Last Working Version

No response

Additional Context

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions