Skip to content

Security: cryptiles #482

@y-lohse

Description

@y-lohse

We currently have a security alert for cryptileshttps://github.com/cozy/cozy-contacts/network/alert/yarn.lock/cryptiles/open

yarn why cryptiles

"cozy-bar#cozy-client-js#pouchdb#request#hawk" depends on it
 - Hoisted from "cozy-bar#cozy-client-js#pouchdb#request#hawk#cryptiles"

This is the same vulnerability than on most of our projects, coming from an old pouchdb version. It only affects the node eversion, so the shipped web app is not at risk.

This will eventually be solved by upgrading pouchdb in cozy-client-js.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions