Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

xmldom security warning - cldr dependency unused? #40

Closed
kulmann opened this issue Dec 15, 2023 · 0 comments
Closed

xmldom security warning - cldr dependency unused? #40

kulmann opened this issue Dec 15, 2023 · 0 comments

Comments

@kulmann
Copy link

kulmann commented Dec 15, 2023

Hey guys, we've had a security warning regarding xmldom in https://github.com/owncloud/ocis - see https://nvd.nist.gov/vuln/detail/CVE-2022-39299

The outdated xmldom package comes from the cldr version you declared as a dependency in your package.json, see https://github.com/Kopano-dev/kpop/blob/master/package.json#L26

However, I can't find any use of cldr in your code base. Even the commit that introduced it doesn't seem to reference the package in any way.

Is it safe to remove the cldr dependency from kpop? In that case I'd happily make a pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

1 participant