Skip to content

Conversation

crudo
Copy link
Contributor

@crudo crudo commented Jan 27, 2022

Checklist

  • Tests added / updated
  • Docs added / updated

Does this PR introduce a breaking change?

  • Yes
  • No

If indicated yes above, please describe the breaking change(s).

Screenshots

n/a

Additional context

GHSA-r683-j2x4-v87g
node-fetch/node-fetch#1453
https://nvd.nist.gov/vuln/detail/CVE-2022-0235

@P0lip P0lip changed the title [Security] CVE-2022-0235 update [email protected] fix(runtime): update node-fetch from ^2.6.1 to ^2.6.7 Jan 31, 2022
Copy link
Contributor

@P0lip P0lip left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@P0lip P0lip added security Pull requests that address a security vulnerability dependencies Pull requests that update a dependency file labels Jan 31, 2022
@P0lip P0lip enabled auto-merge (squash) January 31, 2022 21:31
@P0lip P0lip merged commit 869510f into stoplightio:develop Jan 31, 2022
stoplight-bot pushed a commit that referenced this pull request Feb 1, 2022
# [@stoplight/spectral-runtime-v1.1.2](https://github.com/stoplightio/spectral/compare/@stoplight/spectral-runtime-v1.1.1...@stoplight/spectral-runtime-v1.1.2) (2022-02-01)

### Bug Fixes

* **runtime:** update node-fetch from ^2.6.1 to ^2.6.7 ([#2041](#2041)) ([869510f](869510f))
@stoplight-bot
Copy link
Collaborator

🎉 This PR is included in version @stoplight/spectral-runtime-v1.1.2 🎉

The release is available on npm package (@latest dist-tag)

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file released security Pull requests that address a security vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants