Skip to content
This repository has been archived by the owner on Dec 8, 2022. It is now read-only.

Prototype Pollution / lodash #41

Closed
fredleput opened this issue Apr 14, 2020 · 7 comments
Closed

Prototype Pollution / lodash #41

fredleput opened this issue Apr 14, 2020 · 7 comments
Labels
bug 🐛 Something isn't working support ⛑️ Needed to solve a bug/add feature for an implementor vulnerability Security issue
Projects

Comments

@fredleput
Copy link

Hi,
After installing ol-kit, i've got 3 high vulnerabilities related to loadah dependency. npm audit says it's patched in version >=4.17.12. So, i installed latest version ie : 4.17.15 but vulnerabilities are still there.
Any help appreciated !
thx,
Fred.

@glenselle
Copy link
Contributor

Hey Fred, thanks for reporting this! Some of these issues stem from the fact that ol-kit is depending on OpenLayers 4.6.5 -- we plan to update very soon to use the latest version

@glenselle glenselle added bug 🐛 Something isn't working vulnerability Security issue labels Apr 14, 2020
@fredleput
Copy link
Author

No problem !

@glenselle
Copy link
Contributor

Leaving open til we resolve this

@glenselle glenselle reopened this Apr 15, 2020
@PizzaBrandon PizzaBrandon added the support ⛑️ Needed to solve a bug/add feature for an implementor label Aug 18, 2020
@PizzaBrandon PizzaBrandon added this to To do in Support via automation Aug 18, 2020
@drodenberg drodenberg moved this from To do to In progress in Support Oct 20, 2020
@drodenberg
Copy link
Collaborator

Looking into this now and it looks like one of our vulnerabilities from babel-plugin-inline-react-svg wont be fixed anytime soon... airbnb/babel-plugin-inline-react-svg#45

@drodenberg
Copy link
Collaborator

Vorpal has 3 high vulnerabilities and I have a comment on this waiting to see if this will get resolved. dthree/vorpal#331. Found this as a potential alternative to vorpal. https://github.com/drew-y/cliffy

@drodenberg
Copy link
Collaborator

Those are the only vulnerabilities I have left from what I see

@akuma1
Copy link
Collaborator

akuma1 commented May 17, 2022

We are deprecating ol-kit.
You may consider these alternatives:

  • Use openlayers directly as recent versions of openlayers provides quite a bit of functionality out of box.
  • Additionally , you can take a look at these openlayers libraries.

@akuma1 akuma1 closed this as completed May 17, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
bug 🐛 Something isn't working support ⛑️ Needed to solve a bug/add feature for an implementor vulnerability Security issue
Projects
No open projects
Support
  
In progress
Development

No branches or pull requests

5 participants