Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump socks and pac-resolver versions to mitigate vulnerability in IP package #317

Closed
wants to merge 2 commits into from

Conversation

rjblopes
Copy link
Contributor

@rjblopes rjblopes commented Jun 9, 2024

Revamp of #295 including pac-resolver dependency in pac-proxy-agent.


https://github.com/TooTallNate/proxy-agents/blob/b5f94e3222c0aaa3bc56218ff125e2c56417c86e/packages/socks-proxy-agent/package.json#L112C17-L112C21

Socks has released the new version and removed the ip package because of having a vulnerability mentioned here: GHSA-78xj-cgh5-2h22

Copy link

changeset-bot bot commented Jun 9, 2024

🦋 Changeset detected

Latest commit: 1cc0c72

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 2 packages
Name Type
socks-proxy-agent Patch
pac-proxy-agent Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Copy link

vercel bot commented Jun 9, 2024

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Updated (UTC)
proxy-agents ✅ Ready (Inspect) Visit Preview Jun 9, 2024 4:09pm

@TooTallNate
Copy link
Owner

Your change updates the pnpm lockfile format to a version that is not compatible with the current CI setup. Can you please adjust to retain the old lockfile format?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants