[Pkg-javascript-devel] Bug#1033250: Bug#1033250: Bug#1033250: node-request: CVE-2023-28155

Pirate Praveen praveen at onenetbeyond.org
Tue Mar 21 06:50:24 GMT 2023


Control: block -1 by 956423

On Tue, Mar 21 2023 at 12:05:15 PM +05:30:00 +05:30:00, Pirate Praveen 
<praveen at onenetbeyond.org> wrote:
>> $ reverse-depends node-request
> Reverse-Depends
> ===============
> * node-jsonld
> * node-matrix-js-sdk
> * yarnpkg
> 
> For yarnpkg, we are trying to remove the dependency to node-request, 
> see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=980316#43 
> (hopefully we will be able to remove it for trixie).

Asking yarn upstream as well, if we can remove dependency on request
https://github.com/yarnpkg/yarn/issues/8935



More information about the Pkg-javascript-devel mailing list