-
Notifications
You must be signed in to change notification settings - Fork 142
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Dependency "cb" causing security issues in Nexus because of missing LICENSE file and being 10 years from last update #423
Comments
Looks like the This is trivial to replace with code in IMO, this dependency should definitely be removed. |
thank you so much for the quick reply and fix. When the fix will be released? @adamjmcgrath @kmannislands |
Hey @awacode21 - I'll put out a release next week |
Great thanks! |
👋 @awacode21 - this got released in 2.11.0 |
Describe the problem
We are using express-openid-connect for our project to do the whole auth0 process.
But our production build is no longer able to build because Nexus complains about Security vulnaribilities. It is complaing about the dependency "cb" used by express-openid-connect as it is missing a LICENSE file and that the package is older than 5 years, actually the last update was 10 years ago.
Is there any chance to replace this outdated dependency?
What was the expected behavior?
My project should be able to use express-openid-connect without running into security vulnerabilities. I expect express-openid-connect to use mantained packages and not totally outdated stuff.
LATEST
The text was updated successfully, but these errors were encountered: