Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Rabbot has insecure dependency #82

Closed
mcasimir opened this issue Apr 27, 2017 · 3 comments
Closed

Rabbot has insecure dependency #82

mcasimir opened this issue Apr 27, 2017 · 3 comments

Comments

@mcasimir
Copy link

Rabbot does not pass the security check from nsp:

moment   2.10.2      >=2.11.2   [email protected] > [email protected] > [email protected] > [email protected]   https://nodesecurity.io/advisories/55 
@arobson
Copy link
Owner

arobson commented May 19, 2017

I'm somewhat familiar with this issue. It's pretty unlikely that you're going to trigger it but I know the maintainer of whistlepunk and they'd be open to a PR to patch the moment version if it's something you need in order to use rabbot.

@astanciu
Copy link

astanciu commented Sep 27, 2017

There is a PR submitted to whistlepunk, just been sitting there for almost a year:
LeanKit-Labs/whistlepunk#21

Can we remove this dependency? That project hasn't been updated in 2 years

@loayg
Copy link

loayg commented Oct 31, 2017

@arobson @astanciu
There are 2 vulnerabilities and snyk report has been failing because of these 2 vulnerabilities.
Also, there is a pr here to update debug version:
#110

 debug    2.2.0       >= 2.6.9 < 3.0.0 || >= 3.1.0   [email protected] > [email protected] > [email protected]     https://nodesecurity.io/advisories/534 
 moment   2.10.2      >=2.11.2              [email protected] > [email protected] > [email protected]   https://nodesecurity.io/advisories/55  

Thanks.

arobson pushed a commit that referenced this issue Feb 10, 2018
fix security warning on dependencies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants