AzureDevOpsExtension icon indicating copy to clipboard operation
AzureDevOpsExtension copied to clipboard

Security updates

Open nohwnd opened this issue 5 years ago • 6 comments

@ChrisLGardner please review this, I am getting emails with warnings and it says high severity :)

https://github.com/pester/AzureDevOpsExtension/network/alerts

nohwnd avatar Dec 26 '19 18:12 nohwnd

That page 404's for me. Maybe I need more permissions on the repo?

ChrisLGardner avatar Dec 26 '19 19:12 ChrisLGardner

@ChrisLGardner how about now?

nohwnd avatar Dec 28 '19 09:12 nohwnd

@nohwnd still 404'ing. I can push it to a private repo on my account and see what it pops up with there if it's easier than dealing with the limited permissions Github lets you assign.

ChrisLGardner avatar Dec 28 '19 14:12 ChrisLGardner

It wants you to upgrade http and https proxy from 1.0.0 to at least 2.4.6 (iirc)

nohwnd avatar Dec 28 '19 14:12 nohwnd

I'll see what I can do about that then, it's probably some nested dependency so we'll see if I can upgrade the things using it.

ChrisLGardner avatar Dec 28 '19 14:12 ChrisLGardner

That should be fixed now.

ChrisLGardner avatar Dec 30 '19 15:12 ChrisLGardner