coinpaprika / coinpaprika-api-nodejs-client

This library provides convenient way to use Coinpaprika.com API in NodeJS.
https://api.coinpaprika.com/
MIT License
46 stars 12 forks source link

strange file when coin paprika install on de dependencies #10

Open cSarcasme opened 3 months ago

cSarcasme commented 3 months ago

Hight when i have install coin paprika on my machine i have that error of dependencies on the audit.

Why it does that ?

Thanks for your time and in the wit of your answer i wish you a good day.

# npm audit report

axios  <=0.27.2
Severity: high
Axios vulnerable to Server-Side Request Forgery - https://github.com/advisories/GHSA-4w2v-q235-vp99
axios Inefficient Regular Expression Complexity vulnerability - https://github.com/advisories/GHSA-cph5-m8f7-6c5x
Axios Cross-Site Request Forgery Vulnerability - https://github.com/advisories/GHSA-wf5p-g6vw-rhxx
Depends on vulnerable versions of follow-redirects
No fix available
node_modules/coinpaprika-js/node_modules/axios
  coinpaprika-js  *
  Depends on vulnerable versions of axios
  node_modules/coinpaprika-js

follow-redirects  <=1.15.5
Severity: high
Exposure of Sensitive Information to an Unauthorized Actor in follow-redirects - https://github.com/advisories/GHSA-pw2r-vq6v-hr8c
Exposure of sensitive information in follow-redirects - https://github.com/advisories/GHSA-74fj-2j2h-c42q
Follow Redirects improperly handles URLs in the url.parse() function - https://github.com/advisories/GHSA-jchw-25xp-jwwc
follow-redirects' Proxy-Authorization header kept across hosts - https://github.com/advisories/GHSA-cxjh-pqwp-8mfp
No fix available
node_modules/coinpaprika-js/node_modules/follow-redirects

3 vulnerabilities (1 moderate, 2 high)
marcin-jarota commented 3 months ago

Could you share more details about the runtime environment? Which operating system and node and npm version do you have?

cSarcasme commented 3 months ago

windows 10 nodejs 18.18.2

npm 10.1.0

But my dev have also that error on this system machine when you use coin paprika install in nodejs modules