lirantal / is-website-vulnerable

finds publicly known security vulnerabilities in a website's frontend JavaScript libraries
Apache License 2.0
1.94k stars 111 forks source link

Install via NPM reports Vulnerabilities #85

Closed Fraserhoenes closed 3 years ago

Fraserhoenes commented 3 years ago

Install via NPM reports Vulnerabilities

Expected Behavior

Current Behavior

Possible Solution

Unsure

Steps to Reproduce (for bugs)

See above, and if this is reproducible / if anyone else is getting these vulnerable packages on install, or whether this is a local issue specific to my environment.

Apologies in advance if this isn't an issue with the package, or is only temporary!

Your Environment

lirantal commented 3 years ago

There are indeed 2 issues as we can see here: https://snyk.io/test/github/lirantal/is-website-vulnerable

@Fraserhoenes if you want to suggest a pull request to upgrade the is-url-superb version to latest major I'll be merging it gladly.

Fraserhoenes commented 3 years ago

I'm not crazy experienced but I've forked and I'll give it a go; before committing, check my PR carefully when it comes 😄

lirantal commented 3 years ago

No worries at all, happy to review :-)

lirantal commented 3 years ago

Security vulnerabilities indeed exist here but none of this is a direct issue for the CLI.