Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump es5-ext to version 0.10.64 to resolve CVE-2024-27088 #407

Closed

Conversation

dmgardiner25
Copy link
Member

Changes proposed:

Upgrade the es5-ext package to 0.10.64 to resolve CVE-2024-27088.

I am aware of this previous PR pinning the version, but it doesn't seem like it was working as version 0.10.62 was installed which still includes the war messaging.

Other Tasks:

  • If you updated the Go SDK did you update the PackageVersion in tunnels.go
  • If you updated the TS SDK did you update the dependencies in package.json for connections and management to require a dependency that is > the current published version(Found using npm view @microsoft/dev-tunnels-contracts). This will fix issues where yarn will pull the old version of packages and will cause mismatched dependencies. See example PR

@dmgardiner25
Copy link
Member Author

Closing in favor of #412

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant