Skip to content

Bump ip from 2.0.0 to 2.0.1 #325

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
May 7, 2025
Merged

Conversation

dlqqq
Copy link
Contributor

@dlqqq dlqqq commented May 6, 2025

ip@2.0.0 (an NPM dependency) is impacted by CVE-2023-42282: GHSA-78xj-cgh5-2h22

This CVE is patched in ip@2.0.1. This PR bumps ip from 2.0.0 to 2.0.1.

@dlqqq
Copy link
Contributor Author

dlqqq commented May 6, 2025

@davidbrochart Can this PR get a v3.0.5 patch release after merge?

@davidbrochart davidbrochart merged commit 9a28796 into jupyter-server:main May 7, 2025
11 of 12 checks passed
@davidbrochart
Copy link
Collaborator

Done: https://github.com/jupyter-server/jupyter_ydoc/releases/tag/v3.0.5.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants