vvo/iron-session

upgrade the cookie dependency

Closed this issue ยท 2 comments

npm audit report

cookie <0.7.0
cookie accepts cookie name, path, and domain with out of bounds characters - GHSA-pxg6-pf52-xh8x
No fix available
node_modules/cookie
iron-session *
Depends on vulnerable versions of cookie
node_modules/iron-session

Can we get an updated ETA on when to expect the cookie dep to be updated? @vvo

vvo commented

Upgraded and released as 8.0.4 ๐Ÿ‘