Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade XML Crypto #1199

Closed
wants to merge 1 commit into from
Closed

Upgrade XML Crypto #1199

wants to merge 1 commit into from

Conversation

AdrianHL
Copy link

This fixes the following issue in a nested dependency GHSA-9pgh-qqpf-7wqj
The fix in xml/crypto has only been pushed in a major version release based on a breaking change; see https://github.com/yaronn/xml-crypto/releases

@peterjdrb
Copy link

+1

1 similar comment
@warteruzannan
Copy link

+1

@benasher44 benasher44 mentioned this pull request Oct 17, 2022
@RopoMen
Copy link

RopoMen commented Oct 20, 2022

This xml-encryption update may potentially contain BREAKING CHANGES because

  1. they self update major version
  2. @xmldom/xmldom states that 0.8.x has BREAKING CHANGES https://github.com/xmldom/xmldom/blob/master/CHANGELOG.md#fixed-6

@AdrianHL
Copy link
Author

@RopoMen I'd assume the pipeline will tell us any errors or incompatibilities once it has run, but it has a green light in #1200

@AdrianHL
Copy link
Author

AdrianHL commented Nov 2, 2022

Any chance of getting this tested and merged? Otherwise we will have to fork and use the fork until this is merged.

@deathstar1708
Copy link

Please help approve and merge this pr , so that the peer dependency of xml-crypto can be upgraded that is currently a vulnerability .

@SnathanP
Copy link

Hello there, any update on the approval of this PR ?

@ellisium
Copy link

+1 any update? we can't stuck on this for 1 month. If no plan to fix it, please communicate it.

@jsdevel
Copy link
Collaborator

jsdevel commented Dec 9, 2022

for some reason the build isn't running. can you rebase or --amend --allow-empty to trigger a build?

@AdrianHL
Copy link
Author

AdrianHL commented Jan 5, 2023

Will close as this was done and merged in #1200

@AdrianHL AdrianHL closed this Jan 5, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

8 participants