Closed
Description
Summary
We have proxy-agent
in our devDependencies
but it is not used anywhere. With the recent CVE on vm2 which is a transitive dependency of the proxy-agent
I could not find any usage in our codebase. I suggest to remove the dependency.
Why is this needed?
Because there is a critical CVE GHSA-cchq-frgv-rjh5 and we don't use it.
Which area does this relate to?
Other
Solution
No response
Acknowledgment
- This request meets Powertools for AWS Lambda (TypeScript) Tenets
- Should this be considered in other Powertools for AWS Lambda languages? i.e. Python, Java, and .NET
Future readers
Please react with 👍 and your use case to help us understand customer demand.
Metadata
Metadata
Assignees
Labels
Type
Projects
Status
Shipped