archimatetool / archi

Archi: ArchiMate Modelling Tool
https://www.archimatetool.com
MIT License
914 stars 267 forks source link

Do These Vulnerable Libraries Pose a Security Risk to Archi Users? #1012

Closed connor-dawson closed 5 months ago

connor-dawson commented 5 months ago

I opened a question on the Archi forum and was told to post my question here.

We scanned the master branch of the archi repository with Mend SCA and found that there are vulnerabilities with the following libraries:

Are there plans to update these libraries to fixed versions? Do these libraries pose security risks for Archi users if they are not fixed?

Thank you

Phillipus commented 5 months ago

Hi, thanks for opening the issue.

I don't have access to Mend SCA so if you could post the reported vulnerabilities that would be useful. A potential vulnerability in one context may not be actually be one when a library is used in another context.

Having said that I have already updated these here:

https://github.com/archimatetool/archi/commit/ea557e75c775ff29cacb81ac58c528c1fc9c978d https://github.com/archimatetool/archi/commit/e1b8f43ce4101589bcb82004806a3fe25aec3109 https://github.com/archimatetool/archi/commit/71b6ff9478cab68437e028756a7f35397f67cfef https://github.com/archimatetool/archi/commit/4a2d698101d5f66cc747e3274510674d4bdcac48

So you could try scanning the master branch again.

connor-dawson commented 5 months ago

Hi Phillipus,

Thank you for the quick response.

I re-scanned the master branch with Mend and there were no vulnerabilities reported. My issue is resolved.

Thank you

connor-dawson commented 5 months ago

Is there a plan to include these changes in an upcoming release? I see the latest release was November 1st which includes the vulnerabilites.

Phillipus commented 5 months ago

These will be in the next version of Archi. When that will be is undecided as there is more work to do on the next version.