# K8s JS Client — request Removal Issue

**Link:** [https://github.com/kubernetes-client/javascript/issues/1031](https://github.com/kubernetes-client/javascript/issues/1031)

## Issue Description

**Describe the bug**
There is a [vulnerability](https://github.com/advisories/GHSA-p8p7-x288-28g6) related to `request` npm package which is a dependency of @kubernetes/client-node. Here’s the npm audit report:

```
# npm audit report

request  *
Severity: moderate
Server-Side Request Forgery in Request - https://github.com/advisories/GHSA-p8p7-x288-28g6
No fix available
node_modules/request
  @kubernetes/client-node  *
  Depends on vulnerable versions of request
  node_modules/@kubernetes/client-node

2 moderate severity vulnerabilities

Some issues need review, and may require choosing
a different dependency.
```

Unfortunately, the GitHub repository is not currently maintained and there are no maintainers who could merge this [PR](https://github.com/request/request/pull/3444). 

Is there any chance we can remove the `request` dependency since it’s deprecated since February 2020.

## Comments

### **mstruebing** (MEMBER) - 2023-03-29T15:30:51Z
This is currently work in progress and the current state is in the `release-1.x` branch.
There is a tag published in the current state but I think it's not yet officially supported and doesn't include all features:
[1.0.0-rc1](https://www.npmjs.com/package/@kubernetes/client-node/v/1.0.0-rc1)

### **brendandburns** (CONTRIBUTOR) - 2023-03-29T20:31:06Z
Closing this as a duplicate of #1020
