Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabilities in dependencies #75

Closed
rsp opened this issue Feb 26, 2019 · 3 comments
Closed

Vulnerabilities in dependencies #75

rsp opened this issue Feb 26, 2019 · 3 comments

Comments

@rsp
Copy link

rsp commented Feb 26, 2019

Both npm audit in projects using doxdox and the Snyk badge in it's readme show that this modules uses vulnerable versions of lodash and handlebars via its own dependencies:
Known Vulnerabilities
My questions are:

  • is this project still maintained?
  • is someone aware of that and going to update dependencies?
  • or if not, are you willing to accept PRs by someonbe who does?

@neogeek I see that you've done some updates to avoid snyk alerts last year but the HEAD of master shows "All checks have failed" on GitHub so I don't know if the master in a working state and I'm not sure that the latest changes are published to npm.

@neogeek
Copy link
Member

neogeek commented Feb 27, 2019

is this project still maintained?

This is the state of an open source project that I promised myself that I would never let any of my projects reach, and yet I have. After finding game development I have definitely let my web-based open source projects fall behind. I aim to do better.

On that note, I plan on going through all of my open source projects, starting with doxdox and doxdox plugins, and updating all dependencies to make sure there no avoidable vulnerabilities.

Thank you for the issue and for using doxdox.

@Rudloff
Copy link

Rudloff commented Oct 13, 2019

Any news on this?

doxdox 3.0.0 is affected by multiple vulnerabilites:

One part of the problem is that you use fixed version constraints instead of something like "handlebars": "^4.1.0", so users don't get security updates.

Rudloff added a commit to Rudloff/openvegemap that referenced this issue Oct 13, 2019
We don't really use it and it has multiple security vulnerabilities

See docsbydoxdox/doxdox#75
@neogeek
Copy link
Member

neogeek commented Jan 25, 2022

The latest preview release ( v4.0.0-preview.1 ) of doxdox has resolved the above security issues.

@neogeek neogeek closed this as completed Jan 25, 2022
georgettodd added a commit to georgettodd/openvegemap that referenced this issue Apr 13, 2022
We don't really use it and it has multiple security vulnerabilities

See docsbydoxdox/doxdox#75
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants