You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Jan 4, 2021. It is now read-only.
Thank you for raising our attention to this issue.
This vulnerability is a concern in case a Javascript payload is sent to the BackEnd in Javascript, which is not the case of our BackEnd server (that is in Java).
Nevertheless, the version of assign-deep is already UpToDate in the next MyScript JS release that should be available in a few weeks.
In the meantime you might want to take the version that is available in the branch corresponding to #23 to get the UpToDate version of assign-deep. This fix is provided as is, without qualification.
Best regards,
MyScript Support.
Sign up for freeto subscribe to this conversation on GitHub.
Already have an account?
Sign in.
The version of
assign-deep
used by the project has an active vulnerability and is recommended to update to the latest version:https://github.com/jonschlinkert/assign-deep/blob/1.0.1/README.md
Would it be possible to upgrade the project to use this new version?
Thanks!
The text was updated successfully, but these errors were encountered: