From 84418ae2731df1446b4925dec41db45e6de05b20 Mon Sep 17 00:00:00 2001 From: "Indospace.io" Date: Mon, 16 Apr 2018 22:17:43 -0700 Subject: [PATCH 1/2] snyk security vuln. - update sshpk version MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ✗ High severity vulnerability found on sshpk@1.13.1 - desc: Regular Expression Denial of Service (ReDoS) - info: https://snyk.io/vuln/npm:sshpk:20180409 - from: node_services@1.0.0 > node-gyp@3.6.2 > request@2.83.0 > http-signature@1.2.0 > sshpk@1.13.1 Your dependencies are out of date, otherwise you would be using a newer sshpk than sshpk@1.13.1. --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index df07d53..3ef2878 100644 --- a/package.json +++ b/package.json @@ -30,7 +30,7 @@ "dependencies": { "assert-plus": "^1.0.0", "jsprim": "^1.2.2", - "sshpk": "^1.7.0" + "sshpk": "^1.14.1" }, "devDependencies": { "tap": "0.4.2", From 8fa4545eca5698d0b2de7e9f70b87552f7854092 Mon Sep 17 00:00:00 2001 From: "Indospace.io" Date: Thu, 7 Jun 2018 02:28:35 -0700 Subject: [PATCH 2/2] Update package.json --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 3ef2878..289323e 100644 --- a/package.json +++ b/package.json @@ -30,7 +30,7 @@ "dependencies": { "assert-plus": "^1.0.0", "jsprim": "^1.2.2", - "sshpk": "^1.14.1" + "sshpk": "^1.14.2" }, "devDependencies": { "tap": "0.4.2",