Skip to content

[SUPPORT]: Trouble upgrading Octokit with dependabot #514

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
1 task done
Van-Romel opened this issue May 22, 2025 · 2 comments
Closed
1 task done

[SUPPORT]: Trouble upgrading Octokit with dependabot #514

Van-Romel opened this issue May 22, 2025 · 2 comments
Labels
Status: Triage This is being looked at and prioritized Type: Bug Something isn't working as documented

Comments

@Van-Romel
Copy link

What happened?

Could you take a look if the opened security issue is already fixed? As I checked the code it seems to be addressed.
It is causing Dependabot failures.

Versions

"@octokit/core": "^7.0.2",
"@octokit/rest": "^21.1.1",
"@octokit/request": "^10.0.0",
"@octokit/request-error": "^7.0.0",
"@octokit/plugin-paginate-rest": "^13.0.0",

Relevant log output

Code of Conduct

  • I agree to follow this project's Code of Conduct
@Van-Romel Van-Romel added Status: Triage This is being looked at and prioritized Type: Bug Something isn't working as documented labels May 22, 2025
@octokit
Copy link

octokit bot commented May 22, 2025

👋 Hi! Thank you for this contribution! Just to let you know, our GitHub SDK team does a round of issue and PR reviews twice a week, every Monday and Friday! We have a process in place for prioritizing and responding to your input. Because you are a part of this community please feel free to comment, add to, or pick up any issues/PRs that are labeled with Status: Up for grabs. You & others like you are the reason all of this works! So thank you & happy coding! 🚀

@Van-Romel
Copy link
Author

Relevant log:

Dependabot cannot update @octokit/request-error to a non-vulnerable version
The latest possible version that can be installed is 3.0.3 because of the following conflicting dependencies:

@octokit/[email protected] requires @octokit/request-error@^6.1.8 via a transitive dependency on @octokit/[email protected]
@octokit/[email protected] requires @octokit/request-error@^6.1.8 via @octokit/[email protected]
@octokit/[email protected] requires @octokit/request-error@^6.1.8 via a transitive dependency on @octokit/[email protected]
@probot/[email protected] requires @octokit/request-error@^3.0.0 via a transitive dependency on @octokit/[email protected]
@probot/[email protected] requires @octokit/request-error@^3.0.0 via a transitive dependency on @octokit/[email protected]
@probot/[email protected] requires @octokit/request-error@^3.0.0 via a transitive dependency on @octokit/[email protected]
@probot/[email protected] requires @octokit/request-error@^3.0.0 via a transitive dependency on @octokit/[email protected]
@probot/[email protected] requires @octokit/request-error@^3.0.0 via a transitive dependency on @octokit/[email protected]
@probot/[email protected] requires @octokit/request-error@^3.0.0 via a transitive dependency on @octokit/[email protected]
@probot/[email protected] requires @octokit/request-error@^3.0.3 via a transitive dependency on @octokit/[email protected]
@probot/[email protected] requires @octokit/request-error@^3.0.0 via a transitive dependency on @octokit/[email protected]
@probot/[email protected] requires @octokit/request-error@^2.0.5 via a transitive dependency on @octokit/[email protected]
@probot/[email protected] requires @octokit/request-error@^2.1.0 via a transitive dependency on @octokit/[email protected]
@probot/[email protected] requires @octokit/request-error@^2.1.0 via a transitive dependency on @octokit/[email protected]
@probot/[email protected] requires @octokit/request-error@^2.0.2 via a transitive dependency on @octokit/[email protected]
No patched version available for @octokit/request-error

The earliest fixed version is 5.1.1.

@wolfy1339 wolfy1339 changed the title [BUG]: Security issue seems to be fixed: Regular Expression in index Leads to ReDoS Vulnerability Due to Catastrophic Backtracking [SUPPORT]: Trouble upgrading Octokit with dependabot May 22, 2025
@wolfy1339 wolfy1339 closed this as not planned Won't fix, can't repro, duplicate, stale May 22, 2025
@github-project-automation github-project-automation bot moved this from 🆕 Triage to ✅ Done in 🧰 Octokit Active May 22, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Status: Triage This is being looked at and prioritized Type: Bug Something isn't working as documented
Projects
Status: ✅ Done
Development

No branches or pull requests

2 participants