Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove dependency on an achived package node-mksnapshot #163

Closed
bizob2828 opened this issue Feb 6, 2019 · 2 comments
Closed

Remove dependency on an achived package node-mksnapshot #163

bizob2828 opened this issue Feb 6, 2019 · 2 comments

Comments

@bizob2828
Copy link

bizob2828 commented Feb 6, 2019

There was a vulnerability in mksnapshot and a PR is opened electron-archive/node-mksnapshot#11, however I'm not sure you all maintain it as it's in the electron-archive org. I want to avoid forking this as well as mksnapshot to fix issue. Any way you could either merge that PR or update this repo to remove that dep?

@jamen
Copy link

jamen commented Feb 8, 2019

Was it archived because its not written in JavaScript?

@Orrison
Copy link

Orrison commented Feb 12, 2019

I second this removal.

The package has been archived in the electron-archive as it has not been updated since Feb 24, 2017 and it contains a vulnerable dependency decompress-zip 0.3.0 https://www.npmjs.com/advisories/777

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants