surge
surge copied to clipboard
⚠️ WARNING ⚠️ tar.gz module has been deprecated and your application is vulnerable
ALERT: npm WARN deprecated [email protected]: ⚠️ WARNING ⚠️ tar.gz module has been deprecated and your application is vulnerable. Please use tar module instead: https://npmjcom/tar
@sintaxi @djanowski I have this issue reported on the ember-cli-surge project also. https://github.com/kiwiupover/ember-cli-surge/issues/104
I believe the issue is related to security too.
Any movement on this? Any project that uses surge, even just for its demo app, is going to cause concern among developers when they see a giant security warning on github due to this dependency.
I have these fixed here, but npm test:local
is failing, so I'm hesitant to make a pull request.
Might as well make a PR and see if it passes in CI. Could be a local issue.
Thanks for talking a look at this. Ill have a peak at your branch. I have a fairly big release in the works. Ill make sure a fix for this issue gets included.
Thanks for talking a look at this. Ill have a peak at your branch. I have a fairly big release in the works. Ill make sure a fix for this issue gets included.
@sintaxi Is it possible to clone the repo, merge the PR, and do a patch release? Then at a later point, do your big release?
As right now, any project that has surge as a dep or dev dep, is getting security notifications from github delivered to the maintainers of the repos.
So getting this fixed immediately would save a lot of time for all the devs that depend on your package.
Any update on this?
Just to emphasise the annoyance of this. I have dozens of repos that have surge as a dev dep. And for each update posted for them, myself and the other maintainers get these alerts:
data:image/s3,"s3://crabby-images/2fdc7/2fdc7fe109e33c0f4742ab3236858ac92826b4a2" alt="screen shot 2018-02-15 at 5 44 48 pm"
data:image/s3,"s3://crabby-images/69ce9/69ce9fd878ac494b8a562dd283c76b8ade584fc8" alt="screen shot 2018-02-15 at 5 44 55 pm"
data:image/s3,"s3://crabby-images/95f0a/95f0acbd18bac6177027ea75bab74ba1aa1ed3ad" alt="screen shot 2018-02-15 at 5 47 26 pm"
data:image/s3,"s3://crabby-images/d7021/d7021e27aa1c6eeec5021fa94dd1fc0596c36f12" alt="screen shot 2018-02-15 at 5 45 27 pm"
If you are new to this error, it takes about 5-15 minutes to debug that the cause is surge.
Multiply this by each surge user.
Working hard on getting this release ready and I agree this is very annoying. Please air your grievances with github because this warning is a false positive and unnecessary in the context of how surge uses the tar lib. Github is overreaching and its extremely frustrating as a library author.
@sintaxi I understand, much love to all open-source maintainers ❤️