chore: address security scanner false positives related to CVE-2023-2968
#437
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Hi there! 👋
First off, great library, we use this over in
archestra-ai/archestra.Docker Scout security scans seem to pick-up
v11.3.0of this library as a false-positive for CVE-2023-2968:(see "Package location" path under the first vulnerability in my screenshot).
I think by simply renaming the
nameofexamples/reconnection/proxy/package.jsonthat should address that?Checklist
npm run test && npm run benchmark --if-present(N/A)and the Code of conduct