High vulnerability with dependency dicer 0.3.1 #6530
Unanswered
hardysabs2
asked this question in
General
Replies: 1 comment
-
See discussion at #6485 This is only a dependency of the outdated Apollo Server 2. Upgrading to AS3 fully resolves this concern. On top of that, the feature that |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Presumably indirect dependencies such as this...
apollo-server > apollo-server-core >
@apollographql/graphql-upload-8-fork > busboy > dicer
...are of very little security risk remaining on dicer v0.3.1 with no current fix for the High audit GHSA-wm7h-9275-46v2?
Can you give any reassurances?
Beta Was this translation helpful? Give feedback.
All reactions