express
express copied to clipboard
Bump qs to 6.9.7 (CVE-2022-24999)
I'm using 5.x, and it still has a dependency on qs 6.9.6, which is vulnerable to prototype pollution. I see you fixed it on master branch with version 6.11.0, but I wasn't sure if it was compatible with this 5.x branch. In doubt, I only bumped the patch version up to the first patched version.
Here's a diff between qs 6.9.6 and 6.9.7.
Hello, and thank you for this. Looks like it is against the wrong branch, but I will move it. Should have a update to the beta with this for you.
Did the beta update happen here? I can't find it.
Hi, also following along for this update to resolve CVE-2022-24999. any updates here @dougwilson @UlisesGascon? Thanks