Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: change ip to resolve the ip's SSRF risk #436

Merged
merged 2 commits into from
Jul 23, 2024

Conversation

easy1090
Copy link
Contributor

Summary

The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses, so need upgrade.
GHSA-2p57-rm9w-gvfp

Related Links

Copy link

netlify bot commented Jul 22, 2024

Deploy Preview for rsdoctor ready!

Name Link
🔨 Latest commit 0a811d9
🔍 Latest deploy log https://app.netlify.com/sites/rsdoctor/deploys/669f50e6f74ea900085f5bc8
😎 Deploy Preview https://deploy-preview-436--rsdoctor.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

@easy1090 easy1090 changed the title chore: update ip version fix: change ip to resolve the ip's SSRF risk Jul 22, 2024
chore: update ip version

chore: update ip version
@easy1090 easy1090 force-pushed the chore/update-ip-dependency branch from 47949ab to 541e839 Compare July 22, 2024 15:26
@easy1090 easy1090 requested a review from chenjiahan July 23, 2024 06:32
@chenjiahan
Copy link
Member

Reduce dependencies is good for install speed 👍

@chenjiahan chenjiahan enabled auto-merge (squash) July 23, 2024 06:42
@chenjiahan chenjiahan merged commit 7b60ff6 into main Jul 23, 2024
7 checks passed
@chenjiahan chenjiahan deleted the chore/update-ip-dependency branch July 23, 2024 06:46
easy1090 added a commit that referenced this pull request Jul 24, 2024
fix(client): module code show error (#441)

chore(deps): update all patch dependencies (#379)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

chore: support rspack 1.x

chore: support rspack 1.x
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants