Skip to content

Bump isomorphic-unfetch in @appsignal/core #621

Closed
@MarkZsombor

Description

@MarkZsombor

The version of isomorphic-unfetch (v3.1.0) used in the current version of @appsignal/core (v1.1.20) is using a library node-fetch v2.6.1 which has a known security venerability. GHSA-r683-j2x4-v87g

Is it possible to bump isomorphic-unfetch to v4 which has the patched version of node-fetch ?

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions