koa-protect icon indicating copy to clipboard operation
koa-protect copied to clipboard

Remove Debug Vulnerability

Open briveramelo opened this issue 4 years ago • 8 comments

upgrading debug to 2.6.9 to eliminate the RegExp DOS low severity vulnerability per https://www.npmjs.com/advisories/534

briveramelo avatar Jun 28 '20 20:06 briveramelo

@may215 very simple change. Would love to hear your thoughts and clear this up

briveramelo avatar Jun 30 '20 23:06 briveramelo

checking back on on this @may215

briveramelo avatar Mar 14 '21 02:03 briveramelo

@may215 @crobinson42 Can you please run npm update on this project to update the dependencies with vulnerabilities and publish an update? There is a certain irony to using a package about protection when it is the only source of known vulnerabilities in a project.

This is a simple fix.

briveramelo avatar Mar 16 '23 17:03 briveramelo

@briveramelo why are you tagging me in your comment? Quit bothersome.

crobinson42 avatar Mar 16 '23 17:03 crobinson42

Are you not a contributor of this project? I imagine you are capable of doing what I've asked

briveramelo avatar Mar 16 '23 17:03 briveramelo

@crobinson42 The other reason, of course, is that it has been almost 3 years since I've requested this update, and now there is a 'high' level vulnerability in this dependency. Ultimately, I aim for a vulnerability-free project, and this is the one outstanding dependency. The fix is simple, but there has been no response.

I'm tagging you so this gets attention.

Accept the merge request.

briveramelo avatar Mar 16 '23 17:03 briveramelo

debug package https://github.com/advisories/GHSA-9vvw-cc9w-f27h https://github.com/advisories/GHSA-w9mr-4mfr-499f https://github.com/advisories/GHSA-gxpj-cx7g-858c

briveramelo avatar Mar 16 '23 17:03 briveramelo

@briveramelo You must not understand what a contributor and npm package owner are. I'll educate you:

Github Repository Contributor

A user who has made a change to a Github repo, ie: PR that is merged into the repo.

NPM Package Owner

A user(s) who has control or ownership of the NPM package to publish new package versions to the NPM repository.


You obviously found my name in the commit history and if you look at it with a little more diligence other than a lazy shotgun approach you would see I only suggested a Slack badge be added to the README.md.

I hope this explanation helps you be less annoying in the future, spread the word.

image

crobinson42 avatar Mar 16 '23 17:03 crobinson42