Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Express dependency has a known vulnerability. An updated version of express is available #1257

Closed
warren-gallagher opened this issue Apr 24, 2024 · 2 comments
Labels

Comments

@warren-gallagher
Copy link

warren-gallagher commented Apr 24, 2024

Version of FoalTS: 4.3.0

Please see vulnerability report: GHSA-rv95-896h-c2vc

@warren-gallagher warren-gallagher changed the title Express dependency has a known vulnerability. An updated version of express is available.e Express dependency has a known vulnerability. An updated version of express is available Apr 24, 2024
@lcnvdl
Copy link
Contributor

lcnvdl commented Apr 25, 2024

Hello Warren. As I understand, this issue will be fixed in FoalTS 4.4.0. The version is about to be published.

@LoicPoullain
Copy link
Member

Hi @warren-gallagher 👋

Yes, v4.4 just has been released to fix this issue. Thank you for reporting this!

For security vulnerabilities, if you could send a message directly to [email protected] the next time, this would be awesome 😄. This way, I'll receive the information directly in my mailbox and the vulnerability won't be disclosed publicly until the fix has been deployed in production. 🙂

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants