alanshaw / david-www

:eyeglasses: David helps keep your Node.js project dependencies up to date.
https://david-dm.org
MIT License
730 stars 131 forks source link

Potential security issues reported by Snyk.io #320

Closed revelt closed 7 years ago

revelt commented 8 years ago

Snyk reports quite alerting issues with this repo: https://snyk.io/test/github/alanshaw/david-www Let's patch up everything that's possible to patch!

gravis commented 8 years ago

Nice! That's indeed a sneaky way to do your advertising...

revelt commented 8 years ago

Well I have no affiliation with Snyk and it's free for OS, so no money's involved anyway 😃 But this doesn't change the subject, Snyk gives instructions what's problematic, so let's fix them if possible

gravis commented 8 years ago

That's exactly what an advertiser would say :)

mk-pmb commented 7 years ago

I think the reason why it looks like ad is that you make it click bait, instead of importing the issues as a todo list. I've tried to do so but failed to extract useful information from the linked site.

███ gives instructions what's problematic,

Its advice for each listed problem is "run our tool to fix it", and the claims of what that tool would do seem to all be about making a modified version of the couchwatch module, because its dependencies are insecure and npm currently has no update for couchwatch.

so let's fix them if possible

I don't think any of those fixes are possible in this module and repo, as they are, to my understanding, all about couchwatch, so that would have to be fixed first. I hope I'm mistaken, because otherwise the OP seems like outright spam really.

revelt commented 7 years ago

ok