moscajs / mosca

MQTT broker as a module
mosca.io
3.2k stars 513 forks source link

Vulerable subdependencies: bl / deep-extend / lodash / stringstream #750

Open mkj28 opened 6 years ago

mkj28 commented 6 years ago

Mosca dependencies pull libraries with security vulnerabilities.

mcollina commented 6 years ago

Those vulnerabilities are not exploitable in Mosca.

mkj28 commented 6 years ago

Those vulnerabilities are not exploitable in Mosca

Fair enough, but mosca pulls them into the deployment

gerad commented 5 years ago

Is it possible to bundle mosca without the stateful functionality? (perhaps exposing it through peer dependencies)?

mcollina commented 5 years ago

You should use https://github.com/mcollina/aedes