-
Notifications
You must be signed in to change notification settings - Fork 28
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security vulnerability #118
Comments
Comment by mitar I think this was already reported 2 years ago. |
I have huge vulnerabilities list
I see fro example that in Are you planing to update dependencies and fix these |
We do plan to bump up the dependencies, but I'm curious - besides the fact that you get this listed when you do npm audit how are those problematic to you? No one can connect to your chimp instance to exploit them, it's not an exposed server. Just the fact that there is a possibility of exploiting a given package doesn't mean there is a possibility to exploit it in any kind of a software that uses that particular package. |
Not problematic. It only looks badly during installation. |
First off, really appreciate your time and effort in adopting this project 👍 🥇
Apart from bloating npm audit et al, it bloats up the nice new GitHub I understand that issue this rather unrelated to this particular project |
Issue by rodrigok
Thursday Jun 07, 2018 at 12:53 GMT
Originally opened as xolvio/chimp#692
Expected behaviour
No security vulnerabilities
Actual behaviour
GitHub alert us about security vulnerability and we could find the source been chimp package.
Version & tools:
chimp -v
0.51.1Join our Slack xolv.io/community #chimp channel, where you can find help and help others.
The text was updated successfully, but these errors were encountered: