Skip to content
This repository has been archived by the owner on Sep 23, 2021. It is now read-only.

address security warnings #29

Closed
stefan-guggisberg opened this issue Sep 17, 2018 · 4 comments
Closed

address security warnings #29

stefan-guggisberg opened this issue Sep 17, 2018 · 4 comments
Assignees

Comments

@stefan-guggisberg
Copy link
Contributor

No description provided.

@stefan-guggisberg stefan-guggisberg self-assigned this Sep 17, 2018
@stefan-guggisberg
Copy link
Contributor Author

there's security warnings regarding hoek. hoek enters the dependency tree via nodegit via node-pre-gyp.

see mapbox/node-pre-gyp#346

@stefan-guggisberg
Copy link
Contributor Author

there are security warnings regarding growl and cryptiles, both indirectly entering the dependency tree via nodegit.

see e.g. nickmerwin/node-coveralls#188

@stefan-guggisberg
Copy link
Contributor Author

the vulnerabilities enter via nodegit.

i've created a PR: nodegit/nodegit#1547

stefan-guggisberg added a commit that referenced this issue Sep 18, 2018
@stefan-guggisberg
Copy link
Contributor Author

for now using nodegit fork which includes fixes for vulnerabilities.

once PR nodegit/nodegit#1547 has been accepted or the vulnerabilities have been fixed otherwise we'll return to using official npm published version of nodegit.

closing issue.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant