Skip to content

nanoid verison is vulnerable to GHSA-mwcw-c2x4-8c55 #218

Open
@marcthe12

Description

@marcthe12

The package uses nanoid 4.0 series which is vulnerable to GHSA-mwcw-c2x4-8c55.

There is a fix with version 5.0.9 which is a major release although from documentation it seem that not porting will be required. Another option is to drop it as it is used in one place so some other api can be used in place (maybe something in node:crypto)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions