Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

17 security issues #4

Open
TheSnowGuru opened this issue Jan 17, 2022 · 7 comments
Open

17 security issues #4

TheSnowGuru opened this issue Jan 17, 2022 · 7 comments

Comments

@TheSnowGuru
Copy link

TheSnowGuru commented Jan 17, 2022

ansi-html
1 ansi-html vulnerability found in package-lock.json 5 days ago
Remediation
No patched version is available.

Details
CVE-2021-23424
high severity
Vulnerable versions: <= 0.0.7
Patched version: No fix
This affects all versions of package ansi-html. If an attacker provides a malicious string, it will get stuck processing the input for an extremely long time.

and I found many other security issues you should attend and fix, thank you!

image

@TheSnowGuru
Copy link
Author

TheSnowGuru commented Jan 17, 2022

  1. immer critical severity
  2. yarn.lock - follow-redirects - high severity
  3. yarn.lock - ansi-html high severity
  4. package-lock.json glob-parent high severity
  5. yarn.lock follow-redirects high severity
  6. package-lock.json ansi-html high severity
  7. yarn.lock postcss moderate severity
  8. yarn.lock ansi-regex moderate severity
  9. yarn.lock react-bootstrap-table moderate severity
  10. package-lock.json json-schema moderate severity
  11. yarn.lock browserslist moderate severity
  12. yarn.lock nth-check moderate severity
  13. yarn.lock postcss moderate severity
  14. package-lock.json node-fetch low severity
  15. package-lock.json node-forge low severity
  16. yarn.lock node-forge low severity
  17. package-lock.json node-fetch low severity

@TheSnowGuru TheSnowGuru changed the title security issues 17 security issues Jan 17, 2022
@codedthemes
Copy link
Collaborator

Hi, Thanks for notifying us. We are working on BS5 at this moment, so we will check if these issues are resolve after that or not.

@TheSnowGuru
Copy link
Author

@codedthemes any news on this?

@codedthemes
Copy link
Collaborator

Not yet. This is in our backlog and we will work on it. In the meantime, if you wanna fix it and create PR, I can appreciate it.

@TheSnowGuru
Copy link
Author

no clue how to , sorry

@codedthemes
Copy link
Collaborator

We have given an update, please check if that works for you. the issues has been reduced from 94 to 22 at this point.

@app-generator
Copy link

@codedthemes ty for the fix!
@TheSnowGuru let us know if you need further assistance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants