We keep getting dependency alerts from github on `...
# ory-network
f
We keep getting dependency alerts from github on
ory/cli
for the
request
package.
Copy code
The request package through 2.88.2 for Node.js and the @cypress/request package prior to 3.0.0 allow a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).

NOTE: The request package is no longer supported by the maintainer.
Would be lovely if this is something that could be addressed.