sintaxi / surge

CLI for the CDN
2.84k stars 135 forks source link

install of surge results in deprecations and vulnerabilities #504

Open johndeighan opened 1 year ago

johndeighan commented 1 year ago
$ cd test

johnd@RazerBlade MINGW64 ~/test
$ npm install surge
npm WARN deprecated har-validator@5.1.5: this library is no longer supported
npm WARN deprecated uuid@3.4.0: Please upgrade  to version 7 or higher.  Older versions may use Math.random() in certain circumstances, which is known to be problematic.  See for details.
npm WARN deprecated request@2.88.2: request has been deprecated, see

added 112 packages in 10s

4 packages are looking for funding
  run `npm fund` for details

johnd@RazerBlade MINGW64 ~/test
$ npm audit
# npm audit report

minimist  1.0.0 - 1.2.5
Severity: critical
Prototype Pollution in minimist -
fix available via `npm audit fix --force`
Will install surge@0.9.0, which is a breaking change
  surge  >=0.1.0
  Depends on vulnerable versions of minimist
  Depends on vulnerable versions of request

request  *
Severity: moderate
Server-Side Request Forgery in Request -
fix available via `npm audit fix --force`
Will install surge@0.9.0, which is a breaking change

3 vulnerabilities (1 moderate, 2 critical)

To address all issues (including breaking changes), run:
  npm audit fix --force

However, even using npm audit fix --force did not clear up the critical vulnerabilities

balupton commented 7 months ago

I use surge to deploy the documentation for the @bevry packages, this has caused all the bevry pakages to be marked as insecure.

balupton commented 7 months ago

dupe of