Skip to content

Conversation

@dlqqq
Copy link
Contributor

@dlqqq dlqqq commented May 6, 2025

ip@2.0.0 (an NPM dependency) is impacted by CVE-2023-42282: GHSA-78xj-cgh5-2h22

This CVE is patched in ip@2.0.1. This PR bumps ip from 2.0.0 to 2.0.1.

@dlqqq
Copy link
Contributor Author

dlqqq commented May 6, 2025

@davidbrochart Can this PR get a v3.0.5 patch release after merge?

@davidbrochart davidbrochart merged commit 9a28796 into jupyter-server:main May 7, 2025
11 of 12 checks passed
@davidbrochart
Copy link
Collaborator

Done: https://github.com/jupyter-server/jupyter_ydoc/releases/tag/v3.0.5.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants