avil13 / vue-sweetalert2

A convenient wrapper for sweetalert2.
https://avil13.github.io/vue-sweetalert2/
656 stars 75 forks source link

Security issue on SweetAlert2 #149

Closed flavio-schoute closed 1 year ago

flavio-schoute commented 2 years ago

Hi,

I just got a notification from my DependaBot about this, under the hood this package is using 11.6.14 version? I am right? I think it is a good idea downgrade to this range if possible. And update to a higher version if the mainter fixed the issue.

image

avil13 commented 1 year ago

Hi. My library is just a wrapper over sweeatalert2. And the author decided to take a different path, even if it goes against humanity. I cannot condemn him. But if I were you, I would look for another library.

https://github.com/sweetalert2/sweetalert2/commits/main/src/SweetAlert.js?author=limonte

image
flavio-schoute commented 1 year ago

Ah okay, thanks for the information.

avil13 commented 1 year ago

@Snicser Do you think it's worth making an alternative to this library, or are there already enough of these?

flavio-schoute commented 1 year ago

Uhmm yes and no, I think if you take good approach to Developer Experience and implments everything well it would be a better package. I think you could this package 100% better.

avil13 commented 6 months ago

Link with diff