-
-
Notifications
You must be signed in to change notification settings - Fork 2.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
unfixable vulnerabilites by npm #3698
Comments
Hi @NewRedsquare, this is due to Etherpad's dependency on swagger-node-express, which has not been updated in a long time. See for example: swagger-api/swagger-node#592 The wisest move would probably be to move to another library altogether. |
So this is in standby now ? |
The vulnerabilities that were fixed on Etherpad from 1.6.4 to 1.8.0 were all fixed in a proper way. The ones that are still there are the ones that require more effort and, thus, time. SOme of them are really nasty to tackle. Obviously not all the vulnerabilities shown by |
@NewRedsquare, it's on the radar, but I can give no timing guarantees. Until we do not get rid of a lot of legacy libraries, these sort of updates will always be problematic. This issue is going to be tracked on #3723. If you have a proposal for an alternative library, please write down a line there. Closing this. |
Hello,
while trying to install etherpad-lite, after doing
npm audit fix
, it gives me "unfixable" vulnerabilities :I just saw that there was similar issues, but i can't find any proper solution. I just understood that you tried "to bypass" those vulnerabilites or am I wrong ?
The text was updated successfully, but these errors were encountered: