Skip to content
This repository was archived by the owner on Nov 18, 2024. It is now read-only.
This repository was archived by the owner on Nov 18, 2024. It is now read-only.

node-fetch vulnerability transitive from isomorphic-fetch #338

@lucasgonze

Description

@lucasgonze

🐛 Bug Report

According to Dependabot, [email protected] (through 0.10.0-rc5-beta) requires node-fetch@^1.0.1 via a transitive dependency on [email protected]. This version of node-fetch has a vulnerability that is fixed in 2.6.7 and later.

isomorphic-fetch is abandoned. Consumers of isomorphic-fetch are moving to an alternative project, cross-fetch. babel-plugin-fbt-runtime should too.

To Reproduce

  1. Add babel-plugin-fbt-runtime to a project
  2. Run Dependabot against the downstream project
  3. View alerts

Expected behavior

node-fetch should be at 2.6.7 or later

Link to repo (highly encouraged) or paste

For security reasons, I can't share this publically. Contact me offline ([email protected]).

Also...

I'd happily submit a patch but am baffled by the structure of this repo. LMK if you want the help.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions