mirror of https://github.com/actions/setup-go.git
You cannot select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
The vulnerability:
$ npm audit --audit-level=high
# npm audit report
form-data >=4.0.0 <4.0.4 || <2.5.4
Severity: critical
form-data uses unsafe random function in form-data for choosing boundary - https://github.com/advisories/GHSA-fjxv-7rqg-78g4
form-data uses unsafe random function in form-data for choosing boundary - https://github.com/advisories/GHSA-fjxv-7rqg-78g4
fix available via `npm audit fix`
node_modules/@azure/core-http/node_modules/form-data
node_modules/@types/node-fetch/node_modules/form-data
node_modules/form-data
1 critical severity vulnerability
To address all issues, run:
npm audit fix
This change is the result of from running `npm audit fix` and then
using[1] to update licenses via `licensed cache`.
It doesn't look like `dependabot` previously raised any PRs for this
dependency, so this bumps it from `4.0.0` to `4.0.4`, see the
changelog[2] for details.
Link: https://github.com/licensee/licensed [1]
Link: https://github.com/form-data/form-data/blob/v4.0.4/CHANGELOG.md [2]
|
2 months ago | |
|---|---|---|
| .. | ||
| @actions | 4 months ago | |
| @azure | 2 years ago | |
| @fastify | 2 years ago | |
| @opentelemetry | 2 years ago | |
| @protobuf-ts | 8 months ago | |
| @types | 2 years ago | |
| abort-controller.dep.yml | 3 years ago | |
| asynckit.dep.yml | 3 years ago | |
| balanced-match.dep.yml | 3 years ago | |
| brace-expansion.dep.yml | 4 months ago | |
| call-bind-apply-helpers.dep.yml | 2 months ago | |
| combined-stream.dep.yml | 3 years ago | |
| concat-map.dep.yml | 3 years ago | |
| delayed-stream.dep.yml | 3 years ago | |
| dunder-proto.dep.yml | 2 months ago | |
| es-define-property.dep.yml | 2 months ago | |
| es-errors.dep.yml | 2 months ago | |
| es-object-atoms.dep.yml | 2 months ago | |
| es-set-tostringtag.dep.yml | 2 months ago | |
| event-target-shim.dep.yml | 3 years ago | |
| events.dep.yml | 3 years ago | |
| form-data-2.5.5.dep.yml | 2 months ago | |
| form-data-4.0.4.dep.yml | 2 months ago | |
| function-bind.dep.yml | 2 months ago | |
| get-intrinsic.dep.yml | 2 months ago | |
| get-proto.dep.yml | 2 months ago | |
| gopd.dep.yml | 2 months ago | |
| has-symbols.dep.yml | 2 months ago | |
| has-tostringtag.dep.yml | 2 months ago | |
| hasown.dep.yml | 2 months ago | |
| math-intrinsics.dep.yml | 2 months ago | |
| mime-db.dep.yml | 3 years ago | |
| mime-types.dep.yml | 3 years ago | |
| minimatch.dep.yml | 3 years ago | |
| node-fetch.dep.yml | 2 years ago | |
| process.dep.yml | 3 years ago | |
| safe-buffer.dep.yml | 2 months ago | |
| sax.dep.yml | 2 years ago | |
| semver-6.3.1.dep.yml | 2 years ago | |
| semver-7.7.1.dep.yml | 6 months ago | |
| tr46.dep.yml | 3 years ago | |
| tslib-1.14.1.dep.yml | 3 years ago | |
| tslib-2.6.2.dep.yml | 2 years ago | |
| tunnel.dep.yml | 5 years ago | |
| typescript.dep.yml | 9 months ago | |
| undici-types.dep.yml | 2 years ago | |
| undici.dep.yml | 4 months ago | |
| uuid.dep.yml | 4 months ago | |
| webidl-conversions.dep.yml | 3 years ago | |
| whatwg-url.dep.yml | 3 years ago | |
| xml2js.dep.yml | 3 years ago | |
| xmlbuilder.dep.yml | 3 years ago | |