BitGo / BitGoJS

BitGo JavaScript SDK
https://developers.bitgo.com/
Apache License 2.0
355 stars 272 forks source link

Vulnerable Outdated Packages being used by the BitGo library #1827

Closed ShiftLefter closed 2 years ago

ShiftLefter commented 2 years ago

Hi team,

Several BitGo library dependencies have severe security issues that haven't been fixed since a long time.

Please give us a remediation plan or upgrade them at the soonest. This can pose serious risks to companies like us who are relying on BitGo for transactions, and hence we implore you to take quick action regarding these, every Critical, High, and Medium severity vulnerabilities in BitGo dependencies, we recommend running npm audit and analysing how to upgrade them to latest versions.

For your reference:

Our security tooling has identified several critical vulnerabilities in Bitgo module dependencies such as:

Please let us know your remediation plans regarding them.

GibsDev commented 2 years ago

Good to see that this is still an issue.

mmcshinsky-bitgo commented 2 years ago

Hi @ShiftLefter. Thank you for your raised issue. We have a couple pending PRs that should see any current dependency vulnerabilities as reported per NPM/Github resolved. Upon resolution, they'll be added to our release candidates versions (rc) until the next official release of each given package.

github-actions[bot] commented 2 years ago

This issue is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 5 days.

github-actions[bot] commented 2 years ago

This issue was closed because it has been stalled for 5 days with no activity.