metro icon indicating copy to clipboard operation
metro copied to clipboard

Several security vulnerabilities detected

Open altany opened this issue 5 years ago • 4 comments

Do you want to request a feature or report a bug? Bug

What is the current behavior? There are 3 security vulnerabilities reported by Github, ws, mem and braces.

There is already one issue open for each package, and two of them have pull requests.

  • ws #413 (pull request: #412)
  • mem #414 (pull request: #438)
  • braces #358

Can you please look into these issues, because Github has notified us of severe vulnerabilities in them?

altany avatar Sep 11 '19 11:09 altany

@motiz88 please could these PR's be included in the next release so that we can resolve the security alerts that many projects are now receiving?

timglass avatar Sep 25 '19 08:09 timglass

Any update on this?

baconcheese113 avatar Oct 22 '19 17:10 baconcheese113

New project using expo-cli but I see this is happening when people are using official cli too. Same usage of outdated packages that have vulnerabilities, even after 10 or so weeks.

Have tried:

  • changing package.json and updating package (mem)
  • keeping original package.json and updating mem
  • using npm-package-update package, which shows several of the main package (e.g. react and react-native) as outdated.

Updating anything breaks the app. Github screams about vulns. The PRs in the op's (@altany) post don't seem to have either been merged or work.

Is this a problem only affecting a tiny minority of users? I'd rather use Vue and Vue-Native but it means having to try to change minds.

PatrickLohan avatar Nov 29 '19 06:11 PatrickLohan

Status?

brodycj avatar Apr 09 '21 18:04 brodycj