Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability in hoek lib #25

Open
akravch opened this issue Apr 30, 2018 · 4 comments
Open

Vulnerability in hoek lib #25

akravch opened this issue Apr 30, 2018 · 4 comments
Assignees
Labels
blocked critical invalid This doesn't seem right

Comments

@akravch
Copy link
Member

akravch commented Apr 30, 2018

Github has sent an automatic vulnerability alert for the repo:

A dependency defined in ClientApp/package-lock.json has known security vulnerabilities and should be updated.

Further details: https://nvd.nist.gov/vuln/detail/CVE-2018-3728

Suggested fix: hoek ~> 5.0.3

Need to find out how the lib can be updated and apply a fix if possible.

@akravch akravch added the invalid This doesn't seem right label Apr 30, 2018
@akravch
Copy link
Member Author

akravch commented Apr 30, 2018

The output of npm ls hoek:

@akravch
Copy link
Member Author

akravch commented Apr 30, 2018

There is an issue for that on angular cli backlog: angular/angular-cli#10480
Need to update angular cli once it is resolved.

@pryabov
Copy link
Collaborator

pryabov commented May 2, 2018

Removed blocked tag in the reason that referred issue in Angular CLI was fixed

@akravch akravch self-assigned this May 16, 2018
@akravch
Copy link
Member Author

akravch commented May 16, 2018

It's blocked again. Angular CLI has been updated, but now there is s dependency from @angular-devkit:

Github issue: angular/angular-cli#10827

I guess we'll have to wait for the node-sass to update the request dependency to 2.86...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
blocked critical invalid This doesn't seem right
Projects
None yet
Development

No branches or pull requests

2 participants