Skip to content
This repository has been archived by the owner on Jun 2, 2022. It is now read-only.

Update version of SlimerJS #54

Open
Sayan751 opened this issue Jun 19, 2018 · 0 comments
Open

Update version of SlimerJS #54

Sayan751 opened this issue Jun 19, 2018 · 0 comments

Comments

@Sayan751
Copy link

The package is using [email protected], which is deprecated. Also there are couple of npm audit vulnerabilities from this version of SlimerJS.

  Moderate        Prototype pollution

  Package         hoek

  Patched in      > 4.2.0 < 5.0.0 || >= 5.0.3

  Dependency of   karma-slimerjs-launcher [dev]

  Path            karma-slimerjs-launcher > slimerjs > request > hawk > boom >
                  hoek

  More info       https://nodesecurity.io/advisories/566


  Moderate        Prototype pollution

  Package         hoek

  Patched in      > 4.2.0 < 5.0.0 || >= 5.0.3

  Dependency of   karma-slimerjs-launcher [dev]

  Path            karma-slimerjs-launcher > slimerjs > request > hawk >
                  cryptiles > boom > hoek

  More info       https://nodesecurity.io/advisories/566


  Moderate        Prototype pollution

  Package         hoek

  Patched in      > 4.2.0 < 5.0.0 || >= 5.0.3

  Dependency of   karma-slimerjs-launcher [dev]

  Path            karma-slimerjs-launcher > slimerjs > request > hawk > hoek

  More info       https://nodesecurity.io/advisories/566


  Moderate        Prototype pollution

  Package         hoek

  Patched in      > 4.2.0 < 5.0.0 || >= 5.0.3

  Dependency of   karma-slimerjs-launcher [dev]

  Path            karma-slimerjs-launcher > slimerjs > request > hawk > sntp >
                  hoek

  More info       https://nodesecurity.io/advisories/566


  Moderate        ReDoS via long string of semicolons

  Package         tough-cookie

  Patched in      >=2.3.0

  Dependency of   karma-slimerjs-launcher [dev]

  Path            karma-slimerjs-launcher > slimerjs > request > tough-cookie

  More info       https://nodesecurity.io/advisories/130


  High            Regular Expression Denial of Service

  Package         tough-cookie

  Patched in      >=2.3.3

  Dependency of   karma-slimerjs-launcher [dev]

  Path            karma-slimerjs-launcher > slimerjs > request > tough-cookie

  More info       https://nodesecurity.io/advisories/525


  Moderate        Remote Memory Exposure

  Package         request

  Patched in      >=2.68.0

  Dependency of   karma-slimerjs-launcher [dev]

  Path            karma-slimerjs-launcher > slimerjs > request

  More info       https://nodesecurity.io/advisories/309


  Moderate        Memory Exposure

  Package         tunnel-agent

  Patched in      >=0.6.0

  Dependency of   karma-slimerjs-launcher [dev]

  Path            karma-slimerjs-launcher > slimerjs > request > tunnel-agent

  More info       https://nodesecurity.io/advisories/598


  Moderate        Memory Exposure

  Package         concat-stream

  Patched in      >=1.5.2 || >=1.4.11 <1.5.0 || >=1.3.2 <1.4.0

  Dependency of   karma-slimerjs-launcher [dev]

  Path            karma-slimerjs-launcher > slimerjs > extract-zip >
                  concat-stream

  More info       https://nodesecurity.io/advisories/597


  Low             Regular Expression Denial of Service

  Package         debug

  Patched in      >= 2.6.9 < 3.0.0 || >= 3.1.0

  Dependency of   karma-slimerjs-launcher [dev]

  Path            karma-slimerjs-launcher > slimerjs > extract-zip > debug

  More info       https://nodesecurity.io/advisories/534

There is already a new version of SlimerJS, namely 1.0.0. It would be great if you release a new version of the package, with updated dependency.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant