Skip to content

Conversation

@thisisamir98
Copy link
Contributor

@thisisamir98 thisisamir98 commented Jul 25, 2024

Description

@koush/wrtc includes ip as a dependency, which is flagged as a high vulnerability, see https://github.com/wireapp/wire-webapp/security/dependabot/129

@sonarqubecloud
Copy link

@thisisamir98 thisisamir98 merged commit b073edf into dev Jul 25, 2024
@thisisamir98 thisisamir98 deleted the use-roamhq-webrtc branch July 25, 2024 15:33
@thisisamir98
Copy link
Contributor Author

Unfortunately removing this dependency did not fully fix this issue as we still 3 dependencies which have a dependency on ip package.

  • jest-jasmine2
  • jest
  • workbox-webpack-plugin

For now we just have to wait until the maintainer of ip publishes a fix for github/advisory-database#4619

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants