strapi / strapi

🚀 Strapi is the leading open-source headless CMS. It’s 100% JavaScript/TypeScript, fully customizable and developer-first.
https://strapi.io
Other
60.6k stars 7.57k forks source link

NOTICE: Formidable Vulnerability is NOT valid #20189

Open derrickmehaffy opened 2 weeks ago

derrickmehaffy commented 2 weeks ago

Since we have seen an uptick in users submitting vulnerability reports and improperly reporting the issue (in violation of our Security Policy) via GitHub issues I am creating this notice to add some clarification.

Several points related to this:

References:


At this time, we Strapi, have no plans to modify dependencies to "resolve" this vulnerability as it should be removed from the various vulnerabilities databases in due time for being invalid.

Any issues or vulnerability reports opened with regards to this package will be immediately closed and locked. If you have questions or concerns about this decision you can comment below or reach out to the Strapi Security Team via security@strapi.io.

derrickmehaffy commented 2 weeks ago

As an update to this the GitHub advisory was revoked today as well: https://github.com/advisories/GHSA-8cp3-66vr-3r4c