Closed GeVic closed 5 years ago
@GeVic Thanks for reporting this!
These two vulnerabilities appear to in fact be the same vulnerability - a DOS attack vector in the ws
dependency. As stated in our documentation, the tutorial server should not be used in a production environment, so the scope for any potential damage due to this vulnerability is zero.
That said, this is a timely reminder to keep our dependencies up to date, so I've gone ahead and created a PR to address this.
Thanks again!
I was trying out cloning this repo and doing install locally, npm install indicated 2 high severity vulnerabilities found. Below is the flashed output on the terminal
@akhenry can you please look into the same. Although I know it's because of the dependencies but it would be good to address it for the beginners.