-
Notifications
You must be signed in to change notification settings - Fork 134
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Snyk: snowflake-connector-nodejs word-wrap 1.2.3 | Snyk ID - SNYK-JS-WORDWRAP-3149973 #454
Comments
Hey Snowflake team. Any update on this from your end? I've seen past issues/prs involving urllib, but doesn't seem like you wanted to tackle this? Version 3 doesn't include the problematic dependencies that seem to be causing multiple vulnerabilities that the version you use is bringing in. |
hey @bgswilde apologies for not being more transparent on this one. behind the curtains we're very much busy with this so I would not say we don't want to tackle this issue. We cannot just simply bump the we're considering short-term workarounds and long-term solutions to address this security issue. Will post here any updates once they are agreed-upon and available. |
@sfc-gh-dszmolka thanks for the update! |
FYI: Upvoting this issue as this vulnerability is also being flagged on our end by snyk: |
(this is still not forgotten and very much on the table. but as you can see in the original PR opened for the original |
The direct dependent (optionator 0.9.3) uses now the fixed lib"@aashutoshrathi/word-wrap". Actual Problem: Problem with semver (os-name is fixed, but seem not to be merged link ) +-- [email protected] |
entirely replacing the dependency which provides the very core functionality of what is in scope is fixing the as there's any new information will post here. thank you everyone for bearing with us ! |
PR is merged (override |
Just want to make you guys aware, some things are getting merged in the word-wrap repo finally to address this. They went with a different solution than PR#33 on there, but this should prevent you from having to use an override. |
Cheers @bgswilde - appreciate the updates you guys are making and for keeping us in the loop |
yup just wanted to share the good news, edit: override reverted in #579 , this concludes the fix which is automatically picked up upon |
Title: Snyk: snowflake-connector-nodejs word-wrap 1.2.3
Additional information on Snyk can be found here: https://snyk.io/org/snowflakedb-sca-scanning-public-repo/project/957b80fa-27c7-404f-98b8-90d7c14dc6ef
Repo: snowflake-connector-nodejs
CVE: CVE-2023-26115
Package Type: js
Package Name: word-wrap
Package Version: 1.2.3
Snyk ID: SNYK-JS-WORDWRAP-3149973
Vulnerability URL: http://security.snyk.io/vuln/SNYK-JS-WORDWRAP-3149973
Severity: medium
Introduced Date: 2023-03-23
Projects with Vulnerability: snowflakedb/snowflake-connector-nodejs:package.json
Target File: package.json
JIRA Ticket: https://snowflakecomputing.atlassian.net/browse/SNOW-767109
The text was updated successfully, but these errors were encountered: