aksonov / aksonov/react-native-router-flux

vulnerability CVE-2020-7598 is introduced by package minimist

Đang mở
#3,781 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
JavaScript
Star
8.9k
Fork
2.1k
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

Hi, @aksonov, a vulnerability CVE-2020-7598 is introduced in react-native-router-flux@4.3.0 via:
● react-native-router-flux@4.3.0 ➔ opencollective@1.0.3 ➔ minimist@1.2.0

However, opencollective is a legacy package, which has not been maintained for about 4 years.
Is it possible to migrate opencollective to other package to remediate this vulnerability?

I noticed several migration records in other js repo for opencollective:

1. in commitizen, version 2.10.1 ➔ 3.0.0, remove opencollective via [commit](https://github.com/commitizen/cz-cli/commit/a70c234d8471af147cc9f7d9d090b6ba2192eb17)
2. in fast-xml-parser, version 3.3.0 ➔ 3.3.1, remove opencollective via [commit](https://github.com/NaturalIntelligence/fast-xml-parser/commit/eceb14e9a4ad322b61c4736afb461c4227e31e3d)
3. in react-slick, version 0.12.1 ➔ 0.12.2, remove opencollective via [commit](https://github.com/akiran/react-slick/commit/d72750d77906be7aff8204625bfe0565cda4d11b)
4. in level, version 3.0.1 ➔ 3.0.2, migrate opencollective to opencollective-postinstall via [commit](https://github.com/Level/level/commit/a7502af82151c3a01e711eb6c603fbcc9b566c65)
5. in ngx-infinite-scroll, version 7.0.1 ➔ 7.1.0, migrate opencollective to opencollective-postinstall via [commit](https://github.com/orizens/ngx-infinite-scroll/commit/5fbc8af8fd51c34ce9bd7fc1c3fd111fec475b31)
6. in inferno, version 7.1.8 ➔ 7.1.9, migrate opencollective to opencollective-postinstall via [commit](https://github.com/infernojs/inferno/commit/0ea17d05dcded3aa187065ea852ce68f6f6c14ac)

Thanks.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.