BreeeZe / rpos

Raspberry Pi Onvif Server
http://breeeze.github.io/rpos
MIT License
643 stars 146 forks source link

Many outdated dependencies? 33 vulnerabilities (13 moderate, 15 high, 5 critical) #161

Open flatsiedatsie opened 1 year ago

flatsiedatsie commented 1 year ago

I followed the installation steps and noticed this:

$ cd rpos
$ npm install
npm WARN skipping integrity check for git dependency ssh://git@github.com/BreeeZe/node-soap.git 
npm WARN deprecated har-validator@5.1.5: this library is no longer supported
npm WARN deprecated uuid@3.4.0: Please upgrade  to version 7 or higher.  Older versions may use Math.random() in certain circumstances, which is known to be problematic.  See https://v8.dev/blog/math-random for details.
npm WARN deprecated request@2.88.2: request has been deprecated, see https://github.com/request/request/issues/3142
npm WARN deprecated urix@0.1.0: Please see https://github.com/lydell/urix#deprecated
npm WARN deprecated source-map-url@0.4.0: See https://github.com/lydell/source-map-url#deprecated
npm WARN deprecated source-map-resolve@0.5.3: See https://github.com/lydell/source-map-resolve#deprecated
npm WARN deprecated resolve-url@0.2.1: https://github.com/lydell/resolve-url#deprecated
npm WARN deprecated node-uuid@1.4.8: Use uuid module instead
npm WARN deprecated chokidar@2.1.8: Chokidar 2 does not receive security updates since 2019. Upgrade to chokidar 3 with 15x fewer dependencies
npm WARN deprecated source-map-resolve@0.6.0: See https://github.com/lydell/source-map-resolve#deprecated

added 589 packages, and audited 590 packages in 1m

28 packages are looking for funding
  run `npm fund` for details

33 vulnerabilities (13 moderate, 15 high, 5 critical)

Should I be worried about that?

RogerHardiman commented 11 months ago

are you able to help update items in the package config JSON file and test?