You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Last week, CVE 2023 42282 was reported for versions up to 2.0.0 of the NPM package ip. As this package, along with its parent dependencies, is bundled with npm, we are unable to directly update them within our project. Despite attempting to upgrade to the latest npm version 10.4.0, the project still references the vulnerable version of the ip package.
Moreover, ip has just recently released version 2.0.1 containing the necessary fix for the vulnerability. So, are there are any plans to release a patched version of npm, in versions 9 or 10, to align with the latest secure version of the ip package ?
The text was updated successfully, but these errors were encountered:
Last week, CVE 2023 42282 was reported for versions up to 2.0.0 of the NPM package
ip
. As this package, along with its parent dependencies, is bundled withnpm
, we are unable to directly update them within our project. Despite attempting to upgrade to the latestnpm
version 10.4.0, the project still references the vulnerable version of theip
package.Moreover,
ip
has just recently released version 2.0.1 containing the necessary fix for the vulnerability. So, are there are any plans to release a patched version of npm, in versions 9 or 10, to align with the latest secure version of theip
package ?The text was updated successfully, but these errors were encountered: