Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Potential security vulnerabilities with hexo-cli dependency package #24

Closed
ShineSmile opened this issue Dec 25, 2017 · 4 comments
Closed

Comments

@ShineSmile
Copy link

I don't know whether hexo will still work after I edit the package.json by myself.

screen shot 2017-12-25 at 6 49 36 pm

screen shot 2017-12-25 at 6 46 17 pm

screen shot 2017-12-25 at 6 46 10 pm

@deadbaed
Copy link

deadbaed commented Jan 1, 2018

yeah i got the same thing. what should we do ?
edit: i never had the warning for ejs , that one seems fine, but uglify-js is still here....

@ShineSmile
Copy link
Author

image
image
Another new one.

@ShineSmile
Copy link
Author

ShineSmile commented Jan 10, 2018

@ploctaux I have committed this issue again at hexojs/hexo#2958

maybe this project is just demo or something else.

@JLHwung
Copy link
Contributor

JLHwung commented Jan 10, 2018

hexo-cli does not depends on mjs or uglify-js, closed in favor of hexojs/hexo#2958 .

@JLHwung JLHwung closed this as completed Jan 10, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants