Automattic / Automattic/node-canvas
OWASP Dependency Check shows vulnerability on libexpat-1.dll
- Dominant language
- JavaScript
- Stars
- 10.7k
- Forks
- 1.2k
- Avg merge
- 4d 8h
- Merged PRs (30d)
- 1
Description
As we run the OWASP Dependency Check/Scan on this node module, the following item has been flagged out.
[https://nvd.nist.gov/vuln/search/results?form_type=Advanced&results_type=overview&search_type=all&cpe_vendor=cpe%3A%2F%3Alibexpat_project&cpe_product=cpe%3A%2F%3Alibexpat_project%3Alibexpat&cpe_version=cpe%3A%2F%3Alibexpat_project%3Alibexpat%3A1](https://nvd.nist.gov/vuln/search/results?form_type=Advanced&results_type=overview&search_type=all&cpe_vendor=cpe%3A%2F%3Alibexpat_project&cpe_product=cpe%3A%2F%3Alibexpat_project%3Alibexpat&cpe_version=cpe%3A%2F%3Alibexpat_project%3Alibexpat%3A1)
Is there anyway to resolve this?
## Your Environment
* Version of node-canvas: 2.8.0
* Windows 10
* Node: v16.13.1
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by identifying how libexpat-1.dll enters the Windows node-canvas 2.8.0 package, then compare its reported version with the linked NVD vulnerability. Done means the dependency scan no longer flags this library, with the Windows packaging path verified.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, node.js
- Domain
- devops, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100