Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

chore: update dependency#285

Open
jannyHou wants to merge 1 commit into
master from
update/pkgcloud
Open

chore: update dependency #285
jannyHou wants to merge 1 commit into
master from
update/pkgcloud

Conversation

@jannyHou

@jannyHou jannyHou commented Jan 15, 2020
edited
Loading

Copy link
Copy Markdown

Update the dependencies:

Solution is from ppproxy@1ab25b6

The vulnerability package path is:
loopback-component-storage@3.6.3 › pkgcloud@2.2.0 › liboneandone@1.2.0 › mocha@2.5.3 › growl@1.9.2

While liboneandone is not maintained anymore, more discussion see pkgcloud/pkgcloud#644, pkgcloud/pkgcloud#675, pkgcloud/pkgcloud#671

pfuri and martynas3336 reacted with thumbs up emoji

Copy link
Copy Markdown
Author

Should fix the vulnerability, see the installation message:

jannyHous-MacBook-Pro:loopback-component-storage jannyhou$ npm i
npm WARN deprecated superagent@3.8.3: Please note that v5.0.1+ of superagent removes User-Agent header by default, therefore you may need to add it yourself (e.g. GitHub blocks requests without a User-Agent header). This notice will go away with v5.0.2+ once it is released.
> ejs@2.7.4 postinstall /Users/jannyhou/Desktop/2019/snyk/loopback-component-storage/node_modules/ejs
> node ./postinstall.js
Thank you for installing EJS: built with the Jake JavaScript build tool (https://jakejs.com/)
npm WARN eslint-plugin-mocha@4.12.1 requires a peer of eslint@^2.0.0 || ^3.0.0 || ^4.0.0 but none is installed. You must install peer dependencies yourself.
added 455 packages from 855 contributors and audited 2594 packages in 34.911s
found 0 vulnerabilities

Copy link
Copy Markdown
Author

Chatted with @raymondfeng , the best solution would be a new release of https://github.com/1and1/oneandone-cloudserver-sdk-nodejs

I contacted the author in 1and1/oneandone-cloudserver-sdk-nodejs#21 (comment), will wait and see if we can use the new release.

Copy link
Copy Markdown

Hey all, I really appreciate all the work that has gone into this package to make Strongloop/Loopback a viable framework.

I'm hoping that this can be merged in sometime soon as I continue to get critical and high warnings via npm audit when it seems like this branch resolves these warnings.

Again, I appreciate all the work! Thanks in advance.

pbalan reacted with thumbs up emoji

pbalan commented Mar 4, 2020

Copy link
Copy Markdown

Waiting for this update too.

Copy link
Copy Markdown
Member

To those who are concerned, we did the analysis and concluded that the reported vulnerability was transitively from an older version of mocha. No runtime code uses that dependency and it's safe even though a warning is issued by npm audit.

We understand the alerts are annoying. We have tried to get it fixed by upstream modules but no success so far. It's a bit frustrating. We'll see if we have to fork the offending modules and release them under new names.

mjaime29 reacted with thumbs up emoji pbalan, hectorleiva, and mjaime29 reacted with heart emoji

pbalan commented Mar 12, 2020

Copy link
Copy Markdown

@raymondfeng I'd like some help with #237 Not sure if I should open a new one.

mjaime29 commented Apr 6, 2020

Copy link
Copy Markdown

Hey all, I really appreciate all the work, Waiting for this update too.

stale Bot commented Jun 5, 2020

Copy link
Copy Markdown

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@stale stale Bot added the stale label Jun 5, 2020

Copy link
Copy Markdown

Is there any update on this? I know that the dependency is not being used, but, the critical thing is very annoying.

mjaime29 and lewie6 reacted with thumbs up emoji mjaime29 reacted with eyes emoji

@stale stale Bot removed the stale label Jun 18, 2020

stale Bot commented Aug 22, 2020

Copy link
Copy Markdown

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@stale stale Bot added the stale label Aug 22, 2020

Copy link
Copy Markdown

Is there any update on this?

@stale stale Bot removed the stale label Aug 24, 2020

Copy link
Copy Markdown

Any update on this issue?

lewie6 commented May 19, 2021

Copy link
Copy Markdown

Hey, any update on this issue?

curioustushar reacted with thumbs up emoji

Copy link
Copy Markdown

Is there any update on this story?

dhmlau commented May 19, 2021

Copy link
Copy Markdown
Member

Just checked the comment @jannyHou posted above: 1and1/oneandone-cloudserver-sdk-nodejs#21 (comment), there's no progress from there.

In the meanwhile, please take a look at @raymondfeng's comment:

No runtime code uses that dependency and it's safe even though a warning is issued by npm audit.

stale Bot commented Jul 21, 2021

Copy link
Copy Markdown

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@stale stale Bot added the stale label Jul 21, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Reviewers

@dhmlau dhmlau dhmlau approved these changes

@agnes512 agnes512 agnes512 approved these changes

@b-admike b-admike Awaiting requested review from b-admike b-admike is a code owner

@hacksparrow hacksparrow Awaiting requested review from hacksparrow hacksparrow is a code owner

+2 more reviewers

@emonddr emonddr emonddr approved these changes

@KevLehman KevLehman KevLehman approved these changes

Reviewers whose approvals may not affect merge requirements

Labels

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

AltStyle によって変換されたページ (->オリジナル) /