Skip to content

Conversation

mhassan1
Copy link
Contributor

This PR bumps xml2js to 0.5.0.

Resolves #4387.

Checklist
  • non-code related change (markdown/git settings etc)

@mhassan1 mhassan1 requested a review from a team as a code owner April 10, 2023 13:51
@trivikr
Copy link
Member

trivikr commented Apr 10, 2023

Verified that the vulnerability was fixed in dependency Leonidas-from-XIV/node-xml2js#663 (comment)

@trivikr trivikr changed the title chore(deps): bump xml2js to 0.5.0 Bump xml2js to 0.5.0 Apr 10, 2023
@trivikr trivikr merged commit 62847a4 into aws:master Apr 10, 2023
@mhassan1 mhassan1 deleted the bump-xml2js branch April 10, 2023 14:28
@ricardofaria-minu
Copy link

this fix has not been published on NPM.

@trivikr
Copy link
Member

trivikr commented Apr 10, 2023

this fix has not been published on NPM.

It will be published with [email protected] today at around 11:30am Pacific.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

xml2js is vulnerable to prototype pollution(short issue description)
4 participants