jsreport / jsreport-pdf-utils

jsreport extension providing pdf operations like merge or concatenation
MIT License
8 stars 4 forks source link

Update node-signpdf version #26

Closed lichutin-st closed 4 years ago

lichutin-st commented 4 years ago

Hello!

Current version of "node-signpdf" refers to vulnerable "node-forge" version. Can you change it to avoid vulnerabilities?

Screen from npm audit

изображение

pofider commented 4 years ago

Hi, we will update this dep during the next release. Please see the notes how we handle vulnerabilities here https://github.com/jsreport/jsreport#vulnerabilities