Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump octokit plugin-paginate-rest to address ReDoS vulnerability #1972

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

mislav
Copy link

@mislav mislav commented Mar 4, 2025

Fixes #1960
Ref. GHSA-h5c3-5r3r-rr8q

Note that npm audit will still show the updated version as vulnerable, even though it is patched: npm/cli#8125. Hopefully Dependabot figures it out.

@mislav mislav requested a review from a team as a code owner March 4, 2025 17:16
@mislav mislav force-pushed the bump-octokit-plugin-paginate-rest branch from 15b08c5 to e735c9b Compare March 7, 2025 10:54
GHSA-h5c3-5r3r-rr8q

Note that `npm audit` will still show the updated version as vulnerable, even
though it is patched. npm/cli#8125
@mislav mislav force-pushed the bump-octokit-plugin-paginate-rest branch from e735c9b to b68cdad Compare March 7, 2025 10:58
@mislav
Copy link
Author

mislav commented Mar 7, 2025

I have pushed a change that additionally bumps @octokit/plugin-rest-endpoint-methods to address the tsc failure. https://github.com/actions/toolkit/actions/runs/13659205450/job/38226562748

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Bump @octokit dependencies to newer versions
1 participant