julianlam / nodebb-plugin-emailer-mailgun

An emailer plugin for NodeBB using Mailgun as a third party service
9 stars 7 forks source link

NPM advises critical issues in dependencies #20

Closed T3P3 closed 2 years ago

T3P3 commented 2 years ago

The last few times upgrading NodeBB I noticed npm advising using npm audit to review some dependencies with issues. I finally had a chance to do that with the upgrade to 1.18.6, there are a couple of critical issues which can apparently be fixed with "npn audit fix --force" but that will "nodebb-plugin-emailer-mailgun@0.2.1" which is clearly not a good idea.

The references issues are: https://github.com/advisories/GHSA-9j49-mfvp-vmhm https://github.com/advisories/GHSA-4c7m-wxvm-r7gc https://github.com/advisories/GHSA-pc5p-h8pf-mvwp https://github.com/advisories/GHSA-8w57-jfpm-945m

Is this something that can be fixed in a future version of the plugin?

julianlam commented 2 years ago

Have published v1.1.0, can you try with that version and let me know if you are able to send emails?

I changed the underlying dependency that connects with Mailgun, so it requires some testing.

T3P3 commented 2 years ago

v1.1.0 appears to be working well with mailgun in my setup. Thanks!

nodebb-misty commented 2 years ago

Great! Thanks for closing the loop on this :)

On Mon, 13 Dec 2021, at 05:21, Tony Lock wrote:

v1.1.0 appears to be working well with mailgun in my setup. Thanks!

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/julianlam/nodebb-plugin-emailer-mailgun/issues/20#issuecomment-992314843, or unsubscribe https://github.com/notifications/unsubscribe-auth/AB4PTOZSBPHU2NSC2MP35ADUQXCKJANCNFSM5ISW3XMQ. Triage notifications on the go with GitHub Mobile for iOS https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675 or Android https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub.