Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Pinned dependencies (Security vulnerability in dicer - CVE-2022-24434) #24

Closed
soulchild opened this issue Jun 10, 2022 · 1 comment · Fixed by #26
Closed

Pinned dependencies (Security vulnerability in dicer - CVE-2022-24434) #24

soulchild opened this issue Jun 10, 2022 · 1 comment · Fixed by #26
Assignees
Labels
dependencies Pull requests that update a dependency file enhancement

Comments

@soulchild
Copy link
Contributor

Is there a reason why all dependencies are pinned to specific versions? Whenever there's a patch-level fix for any of the dependencies, this package needs to be updated as well which kind of defeats the purpose. Also, the maintainer @Sliverb seems to be rather unresponsive, further complicating things in case a new release is necessary.

The reason I'm asking is because there's a nasty security vulnerability in dicer which is used by busboy which is used by multer, and when a fix gets eventually released (hopefully as a patch-level release, i.e. 1.4.x) this package won't pick it up automatically, requiring a manual fix and release.

Or am I missing something here?

@Sliverb
Copy link
Collaborator

Sliverb commented Jul 28, 2022

Hi @soulchild

Sorry I have been MIA. The dependencies were pinned to make sure usage is consistent across pulls. Just a personal preference.

I'm unable to make the change right away, but if you are able to, can up create a PR to update the deps and remove the pins. I'll get it merged right away.

If you would also like to be a maintainer, happy to king you :)

Thanks for raising this issue

@Sliverb Sliverb added enhancement dependencies Pull requests that update a dependency file labels Jul 28, 2022
soulchild added a commit to soulchild/multer-azure-blob-storage that referenced this issue Jul 29, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file enhancement
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants