universalviewer icon indicating copy to clipboard operation
universalviewer copied to clipboard

Mitigate vulnerabilities from using OpenCollective

Open darrowcousc opened this issue 5 years ago • 1 comments

UV version:

 [email protected]

I'm submitting a:

  • [x] bug report
  • [ ] feature request => please use the user stories repo
  • [ ] support request => Please do not submit support requests here, use stackoverflow

Current behavior:

There are a couple of vulnerabilities reported for modules used by OpenCollective 1.0.3. There may not be any possible mitigation in UV - Moving to a later version once OpenCollective has addressed the problems may be a solution?

OpenCollective and lodash Introduced through:

OpenCollective and minimist Introduced through:

Expected behavior:

Mitigated vulnerabilities,

Steps to reproduce:

Related code:

// insert any relevant code here

Other information:

darrowcousc avatar May 08 '20 00:05 darrowcousc

We should remove this dependency. OC have confirmed that they're not going to update it.

edsilv avatar Aug 25 '21 13:08 edsilv

All issues will be triaged for further investigation or closure by the 28 September 2023. If your issue is still relevant and would like for it be investigated further please comment by 14 September 2023.

LlGC-szw avatar Aug 25 '23 11:08 LlGC-szw

Dependency has been removed.

demiankatz avatar Sep 28 '23 15:09 demiankatz