Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

NPM found 1 high severity vulnerability (mongodb must be >=3.1.13) #283

Open
flaforgue opened this issue Nov 25, 2019 · 4 comments
Open

Comments

@flaforgue
Copy link

Hello,

First of all, thanks for your package which seems to be amazing ! I look forward to try it but I would like to warn you about this point : after the installation, NPM audit returns 1 high severity vulnerability. Here is the exact output :

                       === npm audit security report ===                        
                                                                                
                                                                                
                                 Manual Review                                  
             Some vulnerabilities require your attention to resolve             
                                                                                
          Visit https://go.npm.me/audit-guide for additional guidance           
                                                                                
                                                                                
  High            Denial of Service                                             
                                                                                
  Package         mongodb                                                       
                                                                                
  Patched in      >=3.1.13                                                      
                                                                                
  Dependency of   acl                                                           
                                                                                
  Path            acl > mongodb                                                 
                                                                                
  More info       https://nodesecurity.io/advisories/1203                       
                                                                                
found 1 high severity vulnerability in 879816 scanned packages
  1 vulnerability requires manual review. See the full report for details.

Do you think it would be a dependency hard to update ?

Have a nice day.

@eran10
Copy link

eran10 commented Jan 16, 2020

+1

2 similar comments
@abitofcode
Copy link

+1

@josencv
Copy link

josencv commented Feb 20, 2020

+1

@koresar
Copy link

koresar commented Sep 8, 2020

Fixed in my fork acl2. More info here: #285 (comment)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants