cpx icon indicating copy to clipboard operation
cpx copied to clipboard

Several security vulnerabilities in dependency list

Open bennycode opened this issue 3 years ago • 7 comments

cpx defines a lot of vulnerabile dependencies, such as:

  • braces@^1.8.2
  • semver-regex@^2.0.0
  • glob-parent@^2.0.0

Can you please update these deps? @mysticatea

bennycode avatar Feb 14 '22 12:02 bennycode

It also uses [email protected] which has a critical security issue

nick-keller avatar Apr 22 '22 14:04 nick-keller

It also uses shell-quote, could you please update it to the latest as soon as possible?

can anyone please look into this? @mysticatea @k88hudson @igor-toporet @forivall @pdehaan @quilicicf @yassh

AmirHussain93 avatar Jun 22 '22 05:06 AmirHussain93

I wish I could do something but I have no rights on that repository and my one and only PR never got merged :shrug: This repository hasn't seen a change since 2018 anyway, the maintainer probably doesn't receive the notifications anymore... So either we somehow manage to get @mysticatea to have a look (they seem to still be active on GitHub) or we might have to fork...

quilicicf avatar Jun 22 '22 09:06 quilicicf

Hi @quilicicf, thanks for the quick reply. Is there any way to inform the owner other than GitHub?

AmirHussain93 avatar Jun 22 '22 14:06 AmirHussain93

FYI: For time being we switched to https://www.npmjs.com/package/cpx-fixed mentioned in https://stackoverflow.com/questions/54996035/npm-copy-files-with-cpx-in-postinstall-script/59845967#59845967 - but of course it would be better when the "root" issue is addressed in this repository.

leschdom avatar Jun 23 '22 07:06 leschdom

I do not know the author unfortunately, so I have no clue what the best channel is to reach them :-( They didn't share their email on GitHub but it looks like they have a Twitter account with the same handle as on GitHub. Might be worth it to try I guess.

quilicicf avatar Jun 23 '22 09:06 quilicicf