Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

a critical vulnerable reported during the npm #1182

Open
tunerji opened this issue Feb 17, 2024 · 1 comment
Open

a critical vulnerable reported during the npm #1182

tunerji opened this issue Feb 17, 2024 · 1 comment

Comments

@tunerji
Copy link

tunerji commented Feb 17, 2024

npm audit fix
npm WARN audit fix bsock@0.1.11 node_modules/bsock
npm WARN audit fix bsock@0.1.11 is a bundled dependency of
npm WARN audit fix bsock@0.1.11 bcoin@2.2.0 at
npm WARN audit fix bsock@0.1.11 It cannot be fixed automatically.
npm WARN audit fix bsock@0.1.11 Check for updates to the bcoin package.
npm WARN audit fix bweb@0.1.9 node_modules/bweb
npm WARN audit fix bweb@0.1.9 is a bundled dependency of
npm WARN audit fix bweb@0.1.9 bcoin@2.2.0 at
npm WARN audit fix bweb@0.1.9 It cannot be fixed automatically.
npm WARN audit fix bweb@0.1.9 Check for updates to the bcoin package.
npm WARN audit fix bcurl@0.1.10 node_modules/bcurl
npm WARN audit fix bcurl@0.1.10 is a bundled dependency of
npm WARN audit fix bcurl@0.1.10 bcoin@2.2.0 at
npm WARN audit fix bcurl@0.1.10 It cannot be fixed automatically.
npm WARN audit fix bcurl@0.1.10 Check for updates to the bcoin package.

up to date, audited 31 packages in 6s

npm audit report

bsock *
Severity: critical
bsock uses weak hashing algorithms - GHSA-jj93-39pf-7mcf
No fix available
node_modules/bsock
bcurl >=0.0.1
Depends on vulnerable versions of bsock
node_modules/bcurl
bweb >=0.0.1
Depends on vulnerable versions of bsock
node_modules/bweb

3 critical severity vulnerabilities

Some issues need review, and may require choosing
a different dependency.

@scienmanas
Copy link

I would like to work on this, can you assign this to me

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants