MSandeep96 / SoundKeys

An Electron wrapper for Soundcloud [INACTIVE]
MIT License
27 stars 8 forks source link

Vulnerabilities found #8

Open drpeppercan opened 4 years ago

drpeppercan commented 4 years ago

Take this with a grain of salt, I am not a programmer:

added 259 packages from 219 contributors and audited 3 packages in 24.368s
found 3 vulnerabilities (1 high, 2 critical)
npm audit fix
npm WARN deprecated request@2.88.2: request has been deprecated, see https://github.com/request/request/issues/3142

> electron@1.8.8 postinstall /home/javierdl/SoundKeys/node_modules/electron
> node install.js

Downloading SHASUMS256.txt
[============================================>] 100.0% of 5.74 kB (5.74 kB/s)
+ electron@1.8.8
added 16 packages from 12 contributors, removed 14 packages and updated 47 packages in 23.122s

3 packages are looking for funding
  run `npm fund` for details

fixed 25 of 33 vulnerabilities in 258 scanned packages
  6 vulnerabilities required manual review and could not be updated
  1 package update for 2 vulnerabilities involved breaking changes
  (use `npm audit fix --force` to install breaking changes; or refer to `npm audit` for steps to fix these manually)

I really don't like the sound nor the look of this :(

viveksh1 commented 4 years ago

Honestly I don't recommend you use it, it's inactive so of course there are going to be vulnerabilities and security issues.