globalpayments / rxp-js

Global Payments Ecommerce JavaScript Library
MIT License
34 stars 70 forks source link

Malware in rxp-js? #53

Open php3ch0 opened 2 years ago

php3ch0 commented 2 years ago

Just installed package and got a malware critical vulnerability notification

Picture 1

https://github.com/advisories/GHSA-p4fm-f928-rr26

If this a false positive? Please confirm

icemouton commented 2 months ago

This security notice is stil showing up on the latest version from this month. image

image

Please advise ?

ahumulescu commented 2 months ago

Hello,

The advisory is directly linked to the npm library (https://www.npmjs.com/package/rxp-js) which is not owned by Global Payments.

You would want to use the library like you would do it in the old days. Download the final build and reference it in your code via a script tag.