Skip to content

Security Threat - Update st from 1.10 to 1.2.2#110

Open
schloerke wants to merge 1 commit intomapbox:masterfrom
schloerke:st-version
Open

Security Threat - Update st from 1.10 to 1.2.2#110
schloerke wants to merge 1 commit intomapbox:masterfrom
schloerke:st-version

Conversation

@schloerke
Copy link

Update st from 1.10 to 1.2.2 to stop known security threat. Threat description: https://nvd.nist.gov/vuln/detail/CVE-2017-16224

I receive weekly emails from GitHub about st's version number having a known security threat.

GitHub's suggestion was to update st to it's latest version, 1.2.2.

Thank you for your time,
Barret

forwarding from
ISSUE: rstudio/leaflet#585
PR: rstudio/leaflet#575

@dmolineus
Copy link

This security related PR is open for some months now. Is this repository still maintained?

@tmcw
Copy link
Contributor

tmcw commented Dec 7, 2022

This isn't exploitable at all, and only exists in a devDependency. The best course of action would be to silence the security warning.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants