Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Potential security vulnerability in one of the dependencies #136

Closed
sven-mayer opened this issue Jul 30, 2018 · 1 comment
Closed

Potential security vulnerability in one of the dependencies #136

sven-mayer opened this issue Jul 30, 2018 · 1 comment
Assignees
Labels
1. Priority working on Issue that is now beeing worked on

Comments

@sven-mayer
Copy link
Member

Github marked one of the dependencies "hapijs / hoek" as it is known to be a potential security problem. Can we update the dependencies or even dependencies? Or get rid of the dependence? If it even needed in the latest version?

@telion2 telion2 added the working on Issue that is now beeing worked on label Jul 30, 2018
@telion2
Copy link
Collaborator

telion2 commented Jul 30, 2018

Seems that hoek is part of node-gyp. (https://stackoverflow.com/questions/39739626/what-is-node-gyp).
the contributers are already on it. nodejs/node-gyp#1502.
Since node-gyp might play a crucial role in compiling internal node or express packages I dont really know if removing it or a depency is a good idea. I'm still trying to find out if I still can force an update of hoek itself in any way.

telion2 added a commit that referenced this issue Jul 30, 2018
also fixing other vulnabilities from express-vue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
1. Priority working on Issue that is now beeing worked on
Projects
None yet
Development

No branches or pull requests

2 participants