Open giovanni-bertoncelli opened 3 years ago
@giovanni-bertoncelli, thanks for reporting this. Would you like to submit a PR? thanks.
@giovanni-bertoncelli, we're also waiting for security fixes in liboneandone
(see https://github.com/strongloop/loopback-component-storage/pull/285#issuecomment-574837835).
@dhmlau Sorry, I have not so much time to spend on this...
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.
I wanted to report some vulnerabilities that should be fixed before this package gets out of LTS. Here's the list:
minimatch
, path:loopback-component-storage > pkgcloud > liboneandone > mocha > glob > minimatch
, patched in:3.0.2
growl
, path:loopback-component-storage > pkgcloud > liboneandone > mocha > growl
, patched in:1.10.2
debug
, patched in3.1.0
swagger-ui
, fixed in3.20
minimist
, patched in:1.2.3
node-forge
, patched in0.10.0
How to reproduce
npm audit
will show the vulnerabilities.