kokkorojs / kokkoro-plugin-bilibili

哔哩哔哩 (゜-゜)つロ 干杯~-bilibili
MIT License
1 stars 0 forks source link

咱也不懂,上面说有漏洞 #1

Open guyingd opened 2 years ago

guyingd commented 2 years ago

npm i kokkoro-plugin-bilibili

added 40 packages, and audited 94 packages in 7s

9 packages are looking for funding run npm fund for details

3 moderate severity vulnerabilities

Some issues need review, and may require choosing a different dependency.

Run npm audit for details. ~/bot $ npm audit

npm audit report

got <11.8.5 Severity: moderate Got allows a redirect to a UNIX socket - https://github.com/advisories/GHSA-pfrx-2q88-qq97 No fix available node_modules/got bili-api Depends on vulnerable versions of got node_modules/bili-api kokkoro-plugin-bilibili Depends on vulnerable versions of bili-api node_modules/kokkoro-plugin-bilibili

3 moderate severity vulnerabilities

Some issues need review, and may require choosing a different dependency. ~/bot $ npm fund bot └─┬ https://github.com/sindresorhus/got?sponsor=1 │ └── got@10.7.0 ├── https://github.com/sindresorhus/is?sponsor=1 │ └── @sindresorhus/is@2.1.1 └── https://github.com/sponsors/sindresorhus └── get-stream@5.2.0, mimic-response@2.1.0, p-event@4.2.0, responselike@2.0.1, type-fest@0.10.0, clone-response@1.0.3, normalize-url@6.1.0

xueelf commented 2 years ago

不好意思,刚看到 issue,最近加班比较厉害,这段时间都没怎么更新 orz

嘛,这个插件目前是处于半废弃状态,本身是 yumemi 时代的产物,后续移植过来的,会有很多未知的问题
未来是有计划开发 rss 订阅插件,到时候这个仓库基本就没啥用了,不过嘛...什么时候开发好就不一定了( 咕咕咕