Automattic / Automattic/node-canvas

OWASP Dependency Check shows vulnerability on libexpat-1.dll

Open
#1,953 1 comment 0 reactions 0 assignees View on GitHub
Binaries
Dominant language
JavaScript
Stars
10.7k
Forks
1.2k
Avg merge
4d 8h
Merged PRs (30d)
1

Description

As we run the OWASP Dependency Check/Scan on this node module, the following item has been flagged out.
[https://nvd.nist.gov/vuln/search/results?form_type=Advanced&results_type=overview&search_type=all&cpe_vendor=cpe%3A%2F%3Alibexpat_project&cpe_product=cpe%3A%2F%3Alibexpat_project%3Alibexpat&cpe_version=cpe%3A%2F%3Alibexpat_project%3Alibexpat%3A1](https://nvd.nist.gov/vuln/search/results?form_type=Advanced&results_type=overview&search_type=all&cpe_vendor=cpe%3A%2F%3Alibexpat_project&cpe_product=cpe%3A%2F%3Alibexpat_project%3Alibexpat&cpe_version=cpe%3A%2F%3Alibexpat_project%3Alibexpat%3A1)

Is there anyway to resolve this?

## Your Environment
* Version of node-canvas: 2.8.0
* Windows 10
* Node: v16.13.1

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by identifying how libexpat-1.dll enters the Windows node-canvas 2.8.0 package, then compare its reported version with the linked NVD vulnerability. Done means the dependency scan no longer flags this library, with the Windows packaging path verified.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, node.js
Domain
devops, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.