You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The latest Node-Red image v3.1.6-18 contains nested dependency (npm/node_modules/ip) that doesn't pass security scanning because of package version vulnerability. The recommended ip version is v2.0.1, the current one is v2.0.0: https://nvd.nist.gov/vuln/detail/CVE-2023-42282
Seems like only Node v21.7.0 includes the new npm version 10.5.0 which includes the fixed ip v2.0.1.
Is there any chance that you're gonna release the next Node-Red image version using Node v21.7.0 in the very near future?
Thanks
The text was updated successfully, but these errors were encountered:
The latest Node-Red image v3.1.6-18 contains nested dependency (npm/node_modules/ip) that doesn't pass security scanning because of package version vulnerability. The recommended ip version is v2.0.1, the current one is v2.0.0:
https://nvd.nist.gov/vuln/detail/CVE-2023-42282
Seems like only Node v21.7.0 includes the new npm version 10.5.0 which includes the fixed ip v2.0.1.
Is there any chance that you're gonna release the next Node-Red image version using Node v21.7.0 in the very near future?
Thanks
The text was updated successfully, but these errors were encountered: