Skip to content

Version of hono included via downstream dependency opencontrol has multiple vulnerabilities #6190

@gadamson-upco

Description

@gadamson-upco

Note: This duplicates anomalyco/opencontrol#48, posting here as it impacts all recent sst versions? Delete whichever one isn't needed.

The version of hono included as a dependency in opencontrol has two open vulnerabilities, one medium severity and one high:

Because SST also includes opencontrol, it seems like this impacts all recent versions of SST.

sst@3.17.19
  └─┬ opencontrol@0.0.6
    └── hono@4.7.4

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions