Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Morgan is using Debug 2.6.9 dependency which has a known vulnerability #294

Closed
silverthornekevin opened this issue Jun 7, 2024 · 2 comments
Labels

Comments

@silverthornekevin
Copy link

Debug dependency needs to be upgraded to 4.3.5 to remove the vulnerability that exists within it.

Discussion about the vulnerability takes place here: debug-js/debug#737

@dpopp07
Copy link

dpopp07 commented Jan 9, 2025

This is related to the discussion here.

Notably, a comment on that issue points out:

[email protected]+ requires node >= 6.

Since morgan supports Node 0.8.0 and above, resolving this would require a new major.

The aforementioned issue ended up getting closed - @wesleytodd should this one be closed as well?

@bjohansebas
Copy link
Member

We are not affected by this issue, and we also cannot upgrade to that version due to the support for older Node.js

@bjohansebas bjohansebas closed this as not planned Won't fix, can't repro, duplicate, stale Jan 10, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants