guidone / node-red-contrib-chatbot

Visually build a full featured chat bot for Telegram, Facebook Messenger, Whatsapp and Slack with Node-RED. Almost no coding skills required.
http://red-bot.io
930 stars 188 forks source link

Snyk vulnerabilities #617

Open girishghoda opened 1 year ago

girishghoda commented 1 year ago

Title

Snyk vulnerabilities

Description

Some other info

express-sessions NPM was last updated 7 years ago and most of the vulnerabilities introduced from this dependency

levpachmanov commented 1 year ago

Hey @girishghoda, We're part of a startup called Seal Security that mitigates software vulnerabilities in older open source versions by backporting/creating standalone security patches - enabling more straightforward remediation in cases like this. We created an bson@1.0.9-sp1 that's vulnerability-free. As with all of our patches, it's open-source and available for free.

If relevant, check out our GitHub repo if you wish to learn more, or start using our app - it's free to use for open-source projects!.

Please feel free to reach us at info@seal.security if you have any requests/questions.