FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Skip sending the proxyReq event when the expect header is present by jsmylnycky · Pull Request #1447 · http-party/node-http-proxy · GitHub

Skip sending the proxyReq event when the expect header is present - #1447

Merged
jcrugzz merged 2 commits into
masterfrom
hotfix/advisory-1486
May 17, 2020
Merged

Skip sending the proxyReq event when the expect header is present#1447
jcrugzz merged 2 commits into
masterfrom
hotfix/advisory-1486

Conversation

jsmylnycky commented May 15, 2020
edited
Loading

Copy link
Copy Markdown
Contributor

Hotfix for https://www.npmjs.com/advisories/1486

Expecting build error due to Node 6. Waiting for #1397 to be merged to have a clean CI build.

Copy link
Copy Markdown

will anyone merge this if it solves the issue?

Copy link
Copy Markdown

Any ETA on when this is getting merged ?

Copy link
Copy Markdown

@indexzero @jcrugzz looks like this requires your immediate attention

Copy link
Copy Markdown
Member

My children are the only thing that requires immediate attention, sorry. Software happens during normal working hours. Didn't get to this on Friday, therefore it will be tomorrow.

Jarrett may have a moment, I have asked him.

jcrugzz commented May 17, 2020

Copy link
Copy Markdown
Contributor

@jsmylnycky thanks for the work here. Will release this fix in a few

jcrugzz merged commit 335aeeb into master May 17, 2020
jcrugzz deleted the hotfix/advisory-1486 branch May 17, 2020 21:18

jcrugzz commented May 17, 2020

Copy link
Copy Markdown
Contributor

published as 1.18.1

fabb commented May 18, 2020

Copy link
Copy Markdown

Have you informed npm support to whitelist this version? Currently it‘s still blacklisted: https://www.npmjs.com/advisories/1486/versions
The support usually resolves such inquiries within a few hours: security@npmjs.com

Hypnosphi commented May 18, 2020
edited
Loading

Copy link
Copy Markdown

@indexzero that's understandable, sorry for my wording. But the vulnerability seems reported almost 3 months ago. Do you consider adding more core maintainers as an option?

Copy link
Copy Markdown
Contributor Author

@Hypnosphi If you take a look at the top of the Issues page, there's two pinned posts going back to Aug/Sept, basically looking to get more people active with the future of this project. There's been very little activity from folks willing to actually jump in and contribute tho. If it is something you're interested in doing, I suggest you take a look at those posts and leave some comments to get in touch :)

Copy link
Copy Markdown

Just out of curiosity, was the vulnerability actually reported to the maintainers? This would not be the first time nobody knows about the issue until the advisory goes public: sass/node-sass#2816 (comment)

Copy link
Copy Markdown

Have you informed npm support to whitelist this version? Currently it‘s still blacklisted: https://www.npmjs.com/advisories/1486/versions
The support usually resolves such inquiries within a few hours: security@npmjs.com

They've now marked the fixed version as unaffected

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.


Back | FazBrowse Home | New Git URL