-
-
Notifications
You must be signed in to change notification settings - Fork 704
[packages/core] upgrade nanoid to 3.3.8
(CVE-2024-55565)
#1763
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
Hi @madebyfabian , I noticed that the project is currently using Additionally, I notice that the CVE date is showing as March 6, 2025, which appears to be incorrect. Since the project is already using a secure version, I believe this issue can be closed. Thank you for keeping an eye on security concerns! |
Hi @CodeMan62 thanks for your comment! I noticed that the core package here still has https://github.com/triggerdotdev/trigger.dev/blob/main/packages/core/package.json#L191 |
Hii @madebyfabian thanks for giving the confirmation let me create a PR to change this version thanks for pointing me |
I got a dependabot security alert, that the
@trigger.dev/sdk
(via the /core package) npm package uses a nanoid version prior to3.3.8
, which has a vulnerability (see GHSA-mwcw-c2x4-8c55)In my understanding, the core package (due to usage of the sdk package) is running in production code of users, so this incident seems valid.
If you feel this is not important, you can of course close this. Just wanted to bring this to attention :)
The text was updated successfully, but these errors were encountered: