Skip to content
This repository has been archived by the owner on Jan 17, 2023. It is now read-only.

Remove .nsprc after tough-cookie is updated #3532

Closed
ianb opened this issue Sep 21, 2017 · 1 comment
Closed

Remove .nsprc after tough-cookie is updated #3532

ianb opened this issue Sep 21, 2017 · 1 comment
Assignees

Comments

@ianb
Copy link
Contributor

ianb commented Sep 21, 2017

Reverting 8f9dff6

We should track this security warning: https://nodesecurity.io/advisories/525

Once tough-cookie gets past 2.3.2 we'll probably be okay.

ianb added a commit that referenced this issue Sep 21, 2017
@ianb ianb mentioned this issue Sep 21, 2017
jaredhirsch pushed a commit that referenced this issue Sep 21, 2017
jaredhirsch pushed a commit that referenced this issue Sep 21, 2017
@ghost ghost added this to the General Release 57 milestone Sep 25, 2017
@ianb
Copy link
Contributor Author

ianb commented Sep 25, 2017

New toughcookie is out BTW, with a fix

@jaredhirsch jaredhirsch self-assigned this Sep 27, 2017
jaredhirsch added a commit that referenced this issue Sep 27, 2017
As seen in [1], we had to temporarily disable nsp checks due to a
potential vulnerability in tough-cookie. The request library has been
updated to use the updated tough-cookie, and, thanks to loose version
tracking, looks like the fix percolates up to all our deps.

[1] https://circleci.com/gh/mozilla-services/screenshots/3561
@ianb ianb closed this as completed in 0b09f21 Oct 10, 2017
ianb added a commit that referenced this issue Oct 10, 2017
Fix #3532, remove .nsprc file now that tough-cookie has been updated
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants