You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The tunnel-ssh 4.x series, which is a dependency of db-migrate, only supports ssh2 up to 1.4.0: #755. This CVE can be resolved for db-migrate if the tunnel-ssh dependency is upgraded to 5.x (or if tunnel-ssh updates its 4.x dependencies, but it's been a year since 5.x was released).
Expected behavior
The security vulnerability should be addressed.
The text was updated successfully, but these errors were encountered:
For anyone else looking at this, we're not using the tunnel config with db-migrate so we're just overriding the transitive dependency in our package.json:
I'm submitting a...
Current behavior
The vulnerability CVE-2023-48795 requires
ssh2
1.15 and above to fix: mscdex/ssh2#1354The
tunnel-ssh
4.x series, which is a dependency ofdb-migrate
, only supportsssh2
up to 1.4.0: #755. This CVE can be resolved fordb-migrate
if thetunnel-ssh
dependency is upgraded to 5.x (or iftunnel-ssh
updates its 4.x dependencies, but it's been a year since 5.x was released).Expected behavior
The security vulnerability should be addressed.
The text was updated successfully, but these errors were encountered: