balderdashy / balderdashy/sails
25 vulnerabilities require manual review
- Dominant language
- JavaScript
- Stars
- 22.8k
- Forks
- 1.9k
- PR merge metrics
- No merged PRs in 30d
Description
**Sails version**: 1.1.0
**Node version**: 8.15.0
**NPM version**: 6.7.0
**DB adapter name**: N/A
**DB adapter version**: N/A
**Operating system**: Ubuntu 18.04 LTS
Hi,
After installing sails, npm says:
found 25 vulnerabilities (23 low, 2 critical)
Critical │ Command Injection │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ open │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ No patch available │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ sails │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ sails > machinepack-process > open │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://npmjs.com/advisories/663
Critical │ Command Injection │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ open │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ No patch available │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ sails │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ sails > sails-generate > machinepack-process > open │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://npmjs.com/advisories/663
Anyway great framework, thanks.
Contributor guide
Research direction
Reproduce the installation using Sails 1.1.0, Node 8.15.0, and npm 6.7.0, then inspect the reported dependency paths through machinepack-process and sails-generate. Determine which vulnerabilities remain and what change or documented decision would count as resolving this report; the issue currently provides no target file or test.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, node.js
- Domain
- backend, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100