Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

opencollective dependency is end-of-life and transitively depends on vulnerable versions of minimist #96

Open
rjgotten opened this issue Jul 24, 2023 · 0 comments

Comments

@rjgotten
Copy link

rjgotten commented Jul 24, 2023

Describe the bug
Current versions of the react-reactive-form package depend on opencollective@1.0.3
This package is end-of-life -- will not see further updates, yet transitively depends on versions of the the minimist package that are vulnerable to two cases of prototype pollution. By extension this leaves consumers of the react-reactive-form package with a vulnerable version of minimist in their tree.

To Reproduce

  1. Install the react-reactive-form package.
  2. Run npm audit.

Expected behavior
No security vulnerabilities in the package tree by removing the dependency on opencollective.

(Note also that OpenCollective itself actively discourages continued use of their old solutions that hang off of postinstall scripts. They encourage using the built-in npm fund functionality instead.)

@rjgotten rjgotten changed the title opencollective package is end-of-life and transitively depends on vulnerable versions of minimist opencollective dependency is end-of-life and transitively depends on vulnerable versions of minimist Jul 24, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant