Authentication will soon be required to use Sonatype OSS Index
This change improves stability and gives you usage tracking and higher request limits.
Learn what’s changing
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.