Skip to content

bumped up dependencies to address Critical vurability reported - #1

Closed
sanathusk wants to merge 1 commit into
bshada:mainfrom
sanathusk:main
Closed

sanathusk wants to merge 1 commit into
bshada:mainfrom
sanathusk:main

Conversation

@sanathusk

Copy link
Copy Markdown

running npm audit with nse-bse-api version 0.1.3 (current) reports nse-bse-api depends on vulnerable versions of adm-zip. Hence the PR to update nse-bse-api to upgrade dependencies to latest non breaking version which address the adm-zip as well.
Current:

# npm audit report

adm-zip  <0.6.0
Severity: high
adm-zip: Crafted ZIP file triggers 4GB memory allocation - https://github.com/advisories/GHSA-xcpc-8h2w-3j85
No fix available
node_modules/adm-zip
  nse-bse-api  *
  Depends on vulnerable versions of adm-zip
  node_modules/nse-bse-api

2 high severity vulnerabilities

Some issues need review, and may require choosing
a different dependency.```

@sanathusk sanathusk closed this by deleting the head repository Sep 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant