loopback-component-storage icon indicating copy to clipboard operation
loopback-component-storage copied to clipboard

chore: update dependency

Open jannyHou opened this issue 5 years ago • 16 comments

Update the dependencies:

Solution is from https://github.com/ppproxy/loopback-component-storage/commit/1ab25b68910b37bf0dd2db697ec363a804483e8a

The vulnerability package path is: [email protected][email protected][email protected][email protected][email protected]

While liboneandone is not maintained anymore, more discussion see https://github.com/pkgcloud/pkgcloud/issues/644, https://github.com/pkgcloud/pkgcloud/issues/675, https://github.com/pkgcloud/pkgcloud/pull/671

jannyHou avatar Jan 15 '20 18:01 jannyHou

Should fix the vulnerability, see the installation message:

jannyHous-MacBook-Pro:loopback-component-storage jannyhou$ npm i
npm WARN deprecated [email protected]: Please note that v5.0.1+ of superagent removes User-Agent header by default, therefore you may need to add it yourself (e.g. GitHub blocks requests without a User-Agent header).  This notice will go away with v5.0.2+ once it is released.

> [email protected] postinstall /Users/jannyhou/Desktop/2019/snyk/loopback-component-storage/node_modules/ejs
> node ./postinstall.js

Thank you for installing EJS: built with the Jake JavaScript build tool (https://jakejs.com/)

npm WARN [email protected] requires a peer of eslint@^2.0.0 || ^3.0.0 || ^4.0.0 but none is installed. You must install peer dependencies yourself.

added 455 packages from 855 contributors and audited 2594 packages in 34.911s
found 0 vulnerabilities

jannyHou avatar Jan 15 '20 18:01 jannyHou

Chatted with @raymondfeng , the best solution would be a new release of https://github.com/1and1/oneandone-cloudserver-sdk-nodejs

I contacted the author in https://github.com/1and1/oneandone-cloudserver-sdk-nodejs/issues/21#issuecomment-574834558, will wait and see if we can use the new release.

jannyHou avatar Jan 15 '20 20:01 jannyHou

Hey all, I really appreciate all the work that has gone into this package to make Strongloop/Loopback a viable framework.

I'm hoping that this can be merged in sometime soon as I continue to get critical and high warnings via npm audit when it seems like this branch resolves these warnings.

Again, I appreciate all the work! Thanks in advance.

hectorleiva avatar Feb 17 '20 03:02 hectorleiva

Waiting for this update too.

pbalan avatar Mar 04 '20 08:03 pbalan

To those who are concerned, we did the analysis and concluded that the reported vulnerability was transitively from an older version of mocha. No runtime code uses that dependency and it's safe even though a warning is issued by npm audit.

We understand the alerts are annoying. We have tried to get it fixed by upstream modules but no success so far. It's a bit frustrating. We'll see if we have to fork the offending modules and release them under new names.

raymondfeng avatar Mar 04 '20 21:03 raymondfeng

@raymondfeng I'd like some help with https://github.com/strongloop/loopback-component-storage/issues/237 Not sure if I should open a new one.

pbalan avatar Mar 12 '20 16:03 pbalan

Hey all, I really appreciate all the work, Waiting for this update too.

mjaime29 avatar Apr 06 '20 17:04 mjaime29

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

stale[bot] avatar Jun 05 '20 17:06 stale[bot]

Is there any update on this? I know that the dependency is not being used, but, the critical thing is very annoying.

KevLehman avatar Jun 18 '20 21:06 KevLehman

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

stale[bot] avatar Aug 22 '20 20:08 stale[bot]

Is there any update on this?

mjaime29 avatar Aug 24 '20 13:08 mjaime29

Any update on this issue?

AgostinoArcasensa avatar Oct 31 '20 10:10 AgostinoArcasensa

Hey, any update on this issue?

lewie6 avatar May 19 '21 06:05 lewie6

Is there any update on this story?

Gayathri-Nadimpalli avatar May 19 '21 08:05 Gayathri-Nadimpalli

Just checked the comment @jannyHou posted above: https://github.com/1and1/oneandone-cloudserver-sdk-nodejs/issues/21#issuecomment-574834558, there's no progress from there.

In the meanwhile, please take a look at @raymondfeng's comment:

No runtime code uses that dependency and it's safe even though a warning is issued by npm audit.

dhmlau avatar May 19 '21 23:05 dhmlau

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

stale[bot] avatar Jul 21 '21 02:07 stale[bot]