Skip to content

transitive dependency @tootallnate/once has an advisory and is flaged as a low vulnerability #1835

@q42jaap

Description

@q42jaap

Unable to update dependency on vulnerable npm package. I tried doing this with dependabot in my project:

Dependabot cannot update @tootallnate/once to a non-vulnerable version The latest possible version that can be installed is 2.0.0 because of the following conflicting dependencies:
firebase-functions-test@3.4.1 requires @tootallnate/once@2 via a transitive dependency on http-proxy-agent@5.0.0
firebase-functions@7.0.5 requires @tootallnate/once@2 via a transitive dependency on http-proxy-agent@5.0.0
firebase-admin@13.6.1 requires @tootallnate/once@2 via a transitive dependency on http-proxy-agent@5.0.0
No patched version available for @tootallnate/once The earliest fixed version is 3.0.1.

GitHub advisory: GHSA-vpq2-c234-7xj6

http-proxy-agent is currently at 8.0.0.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions