Version of @tensorflow/tfjs-core is outdated and depends on vulnerable node-fetch
See original GitHub issueThere is a vulnerability in node-fetch
which has been patched and the latest @tensorflow/tfjs-core
pulls the patched version, however the version of @tensorflow/tfjs-core
used in this repo is outdated and therefore does not pull the patch. Would it be possible to upgrade @tensorflow/tfjs-core
?
Issue Analytics
- State:
- Created 2 years ago
- Comments:8 (8 by maintainers)
Top Results From Across the Web
tf-core depends on a node-fetch with vulnerabilities #3931
Because it is a ~ dependency, npm update doesn't update node-fetch to 2.6.1 which is the version that fix the vulnerability described in...
Read more >tfjs-core-fetch-fix - npm Package Health Analysis - Snyk
The npm package tfjs-core-fetch-fix was scanned for known vulnerabilities and missing license, and no issues were found. Thus the package was deemed as...
Read more >@tensorflow/tfjs-core - npm
Hardware-accelerated JavaScript library for machine intelligence. Latest version: 4.1.0, last published: a month ago.
Read more >How to fix node.js vulnerabilities - Stack Overflow
Below are the vulnerabilities that I get: -You can see that all vulnerabilities depend on node-fetch <=2.6.6 When I look upon how to...
Read more >@tensorflow/tfjs-core | Yarn - Package Manager
Execute native TensorFlow with the same TensorFlow.js API under the Node.js runtime.
Read more >Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start FreeTop Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
Top GitHub Comments
I think today.
@marian-r I have created a fix for you in the
hidden-markov-model
repo. When it releases you can start updating this repo 😄