Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update all dependencies + resolve vulns reported by npm #1714

Open
surfaceflinger opened this issue Apr 23, 2024 · 0 comments
Open

Update all dependencies + resolve vulns reported by npm #1714

surfaceflinger opened this issue Apr 23, 2024 · 0 comments

Comments

@surfaceflinger
Copy link

77 vulnerabilities (2 low, 13 moderate, 55 high, 7 critical)

lots of outdated dependencies, it just doesn't look good for a software meant to manage money

for an example, electron

Electron, too, spun into action and released new versions the same day: If your app renders any user-provided content, you should update your version of Electron - v27.0.0-beta.2, v26.2.1, v25.8.1, v24.8.3, and v22.3.24 all contain a fixed version of libwebp, the library responsible for rendering webp images.

v23 which is used isn't mentioned so this isn't clear, let's assume it can probably be bomb'd with a malicious nft due to outdated libwebp/libvpx.

I guess it would be a good idea to not only update everything but also work on dropping as many deps as possible

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant