Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Known critical severity security vulnerability detected in mariadb #8

Closed
mjcampagna opened this issue Aug 15, 2018 · 4 comments
Closed

Comments

@mjcampagna
Copy link

I received this notice from Github:

Known critical severity security vulnerability detected in mariadb <= 1.0.2 defined in package-lock.json.
@knoxcard
Copy link
Contributor

@rusher
Copy link
Collaborator

rusher commented Aug 20, 2018

"mariadb" package name was previously used for other projects totally different from MariaDB, and blocked by npm. Package name was reserved by npm to avoid any malicious use.
1.0.2 correspond to one of those npm blocked release.

Ffor now, i'm in contact with npm support to know if those can totally be removed.

@knoxcard
Copy link
Contributor

close ticket?

@rusher
Copy link
Collaborator

rusher commented Aug 21, 2018

closing ticket, but this will be followed here

@rusher rusher closed this as completed Aug 21, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants