Tracking issue: remove http-parser
#317263
Labels
1.severity: security
Issues which raise a security issue, or PRs that fix one
5. scope: tracking
Long-lived issue tracking long-term fixes or multiple sub-problems
http-parser
is an abandoned project as of November 2022 and considering it's meant to parse arbitrary input over HTTP, keeping the package around likely constitutes a security risk. Though there aren't open publicised CVEs that I could find forhttp-parser
itself, the followup projectllhttp
does in fact have several CVEs, which ups the risk for an abandoned project IMO.Current dependents are:
The text was updated successfully, but these errors were encountered: