-
Notifications
You must be signed in to change notification settings - Fork 80
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Roadmap/Plans #69
Comments
This project appears to be abandoned and contain security vulnerabilities. |
it seems so, any open source alternatives that you know about? |
In my understanding the only issue is lack of user login / authentication. Even without further development, it's still a useful app which can continue to be used with some authentication in front of it. I used it for a while with just HTTP Auth via nginx reverse proxy. |
User authentication is another issue, however, simply adding such authentication would not automatically patch vulnerability (CVE-2023-23277), although it would limit it's exploitability. I will also add that this project's packages are not being updated, which could potentially introduce more vulnerabilities. Update:This repository contains dependencies with serious vulnerabilities (see Table 1). Table 1: OSV scanner results for snippet-box
|
Can someone fork the repo and update the packages. |
First off, thank you @pawelmalak for a great app.
I have been using it on self-hosted VPS in native Docker for 2 years.
It's a really useful resource.
I'm moving most of my self-hosted to the Cloudron PaaS (https://cloudron.io) as it's a great platform for self-hosting.
I've just packaged Snippet-Box for deployment on Cloudron (https://git.cloudron.io/timconsidine/snippet-box-cloudron) for my own use and to help others if you want to deploy it.
Packaging on Cloudron adds an 'out of the box' authentication.
Would you be able to share if you have plans for further development or added features ?
The text was updated successfully, but these errors were encountered: