Skip to content

Can you backport the prototype pollution fix to v11? #8167

@dstapleton92

Description

@dstapleton92

Clear and concise description of the problem

Hi there! The recent prototype pollution fix in this commit was only released for v12. My team is planning to upgrade our projects to v12, but it's going to take us a bit longer because the work is distributed across many repos and the effort has to be synchronized. Would it be possible to backport that fix to v11?

I understand not developing new features for v11, but it seems like the case could be made to backport a fix for a critical vulnerability in a version less than a year old.

Thanks for the consideration!

Suggested solution

Apply the same fix to the v11 code and publish a new 11.x.x release

Alternative

No response

Additional context

No response

Validations

  • Follow our Code of Conduct
  • Read the docs.
  • Check that there isn't already an issue that request the same feature to avoid creating a duplicate.

Would you like to open a PR for this feature?

  • I'm willing to open a PR

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions