Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update v10.x of @nestjs/common for remote execution vuln #14890

Closed
1 task done
phlogisticfugu opened this issue Apr 1, 2025 · 0 comments
Closed
1 task done

update v10.x of @nestjs/common for remote execution vuln #14890

phlogisticfugu opened this issue Apr 1, 2025 · 0 comments
Labels
needs triage This issue has not been looked into type: enhancement 🐺

Comments

@phlogisticfugu
Copy link

Is there an existing issue that is already proposing this?

  • I have searched the existing issues

Is your feature request related to a problem? Please describe it

We're currently on Nest.js 10.x due to a limitation on the version of Node.js we are using (have to use v18 due to AWS limitation on AppRunner)

However, we're currently getting this security vulnerability alert: GHSA-cj7v-w2c7-cp7c

Describe the solution you'd like

Even though this is for the last release, could we please backport the security fix to the v10.x version of Nest.js?

Teachability, documentation, adoption, migration strategy

request to update the github advisory accordingly after a backport of the patch

What is the motivation / use case for changing the behavior?

enables us to use Nest.js securely even though we are on a slightly older version

@phlogisticfugu phlogisticfugu added needs triage This issue has not been looked into type: enhancement 🐺 labels Apr 1, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
needs triage This issue has not been looked into type: enhancement 🐺
Projects
None yet
Development

No branches or pull requests

2 participants