signalfx/signalfx-nodejs

Security vulnerability with ws

Closed this issue · 1 comments

mitom commented

The ws version required is ancient and contains a security vulnerability which was fixed years ago in later versions https://nodesecurity.io/advisories/550

The current version is 6 major versions behind the latest one.

Please upgrade the dependency with urgency.

@mitom Thanks for reporting. We're tracking this internally and will update that dependency as soon as possible.