SocketCluster / socketcluster-client

JavaScript client for SocketCluster
MIT License
293 stars 91 forks source link

Denial of Service security vulnerability according to npm audit #116

Closed happilymarrieddad closed 6 years ago

happilymarrieddad commented 6 years ago

Security vulnerability.

https://nodesecurity.io/advisories/550

jondubois commented 6 years ago

@happilymarrieddad it seems to affect a different version though. On the report you linked, it says Patched: >= 1.1.5 <2.0.0 || >=3.3.1 but I guess we can upgrade anyway.

happilymarrieddad commented 6 years ago

that's what I get for not paying attention

happilymarrieddad commented 6 years ago

Why is NPM complaining then.. very annoying lol

jondubois commented 6 years ago

Ah yeah all these security vulnerability services are driving me insane. They often claim that there is a vulnerability but it's almost never relevant to the project.

It's probably a strategy that these services use to create fear and sell subscriptions.

happilymarrieddad commented 6 years ago

I'm just going to close this. Sorry man.