Remove proxy-agent, not used#219
Merged
Merged
Conversation
proxy-agent was made redundant after #172, which introduced v3 of aws-sdk. This meant that any proxy-related config was done on the `AWS.CloudwatchLogs` instance, rather than on `WinstonCloudwatch` Removing this dependency avoids a critical vulnerability with vm2, inherited via proxy-agent and its dependencies. Fixes #218 Supersedes #216
Contributor
Author
|
@lazywithclass - thanks for your stewardship of this package over the years. Given the current response to vm2, it would be helpful for us to resolve this false positive soon, so that teams dependent on this package can move on and focus on genuine issues relating to vm2. Would you be kind enough to either vet this PR and cut a release with it if it passes muster, or grant the needed privileges for me to do so? Thanks in advance. |
Owner
|
winston-cloudwatch@6.2.0 is out. Thank you for your patience and effort helping the project. |
6 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
proxy-agent was made redundant after #172, which introduced v3 of aws-sdk. This meant that any proxy-related config was done on the
AWS.CloudwatchLogsinstance, rather than onWinstonCloudwatchRemoving this dependency avoids a reported critical vulnerability with vm2, inherited via proxy-agent and its dependencies. Note that this vulnerability can not actually be triggered, given that winston-cloudwatch no longer uses proxy-agent.
Fixes #218
Supersedes #216
Acknowledgements
This PR is submitted as part of work for @opengovsg (Open Government Products, Singapore).