Skip to content

Conversation

@iwko
Copy link

@iwko iwko commented Oct 18, 2018

This is fix for #79

@k001
Copy link

k001 commented Jan 30, 2019

Any ETA to apply this fix?

@iwko
Copy link
Author

iwko commented Jan 31, 2019

@arekinath

@eran10
Copy link

eran10 commented Feb 13, 2019

Any ETA to apply this fix?

@davidlehn
Copy link
Contributor

"Fix"? This patch locks sshpk to a version released in 2015 just to support Node.js 0.8.28 released in 2014? Seems like you're on your own for an edge case like this.

@ejoubaud
Copy link

ejoubaud commented Jun 5, 2019

👎 to this, sshpk < 1.13.2 has an identified vulnerability: https://hackerone.com/reports/319593 This change would cause any project using this lib even indirectly to get audit failures and vulnerability alerts.

@spanditcaa spanditcaa mentioned this pull request Oct 22, 2019
@kusor
Copy link
Contributor

kusor commented Oct 30, 2019

Done as of PR #86

@kusor kusor closed this Oct 30, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants