Skip to content

transitive dependency @tootallnate/once has an advisory and is flaged as a low vulnerability #1835

Description

@q42jaap

Unable to update dependency on vulnerable npm package. I tried doing this with dependabot in my project:

Dependabot cannot update @tootallnate/once to a non-vulnerable version The latest possible version that can be installed is 2.0.0 because of the following conflicting dependencies:
firebase-functions-test@3.4.1 requires @tootallnate/once@2 via a transitive dependency on http-proxy-agent@5.0.0
firebase-functions@7.0.5 requires @tootallnate/once@2 via a transitive dependency on http-proxy-agent@5.0.0
firebase-admin@13.6.1 requires @tootallnate/once@2 via a transitive dependency on http-proxy-agent@5.0.0
No patched version available for @tootallnate/once The earliest fixed version is 3.0.1.

GitHub advisory: GHSA-vpq2-c234-7xj6

http-proxy-agent is currently at 8.0.0.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions