ammo @2.0.4
HTTP Range processing utilities
Maintainers
Keywords
Dev Dependencies (3)
| Package | Constraint | Registry Status |
|---|---|---|
| lab | 13.x.x | auto_approved |
| code | 4.x.x | auto_approved |
| wreck | 12.x.x | auto_approved |
Transitive Dependency Tree
Changes from v1.0.1
Dependency Changes
| Change | Package | Version |
|---|---|---|
| changed | boom | 2.x.x → 5.x.x |
| changed | hoek | 2.x.x → 4.x.x |
File Changes
Risk Dispositions (1 applicable to this version, 0 other)
Accepted rules are downgraded to INFO on future analyses; rejected rules escalate to CRITICAL.
| Rule | Source | Disposition | Author | Reason | |
|---|---|---|---|---|---|
osv:GHSA-mg85-8mv5-ffjr |
osv | reject | AI | AI (osv): Advisory covers all versions of ammo (>= 0.0.0) with no fix; package is deprecated with no planned remediation. Verdict generalizes to every version of this package. |
SAST Findings (2)
[Always reject] All versions of `ammo` are vulnerable to Denial of Service. The Range HTTP header parser has a vulnerability which will cause the function to throw a system error if the header is set to an invalid value. Because hapi is not expecting the function to ever throw, the error is thrown all the way up the stack. If no unhandled exception handler is available, the application will exist, allowing an attacker to shut down services. ## Recommendation This package is deprecated and is now maintained as `@hapi/ammo`. Please update your dependencies to use `@hapi/ammo`.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
Review Summary
Risk score: 56. Findings: 1 critical (+40), 1 medium (+10), 2 low (+6).
Commit: 964248e13958 Browse source
Published to npm: