balderdashy / balderdashy/sails

25 vulnerabilities require manual review

Open
#4,587 2 comments 0 reactions 0 assignees View on GitHub
does this answer your question?
Dominant language
JavaScript
Stars
22.8k
Forks
1.9k
PR merge metrics
No merged PRs in 30d

Description

**Sails version**: 1.1.0
**Node version**: 8.15.0
**NPM version**: 6.7.0
**DB adapter name**: N/A
**DB adapter version**: N/A
**Operating system**: Ubuntu 18.04 LTS



Hi,
After installing sails, npm says:
found 25 vulnerabilities (23 low, 2 critical)

Critical │ Command Injection │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ open │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ No patch available │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ sails │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ sails > machinepack-process > open │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://npmjs.com/advisories/663

Critical │ Command Injection │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ open │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ No patch available │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ sails │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ sails > sails-generate > machinepack-process > open │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://npmjs.com/advisories/663

Anyway great framework, thanks.

Contributor guide

Open the contributing guide

Research direction

Reproduce the installation using Sails 1.1.0, Node 8.15.0, and npm 6.7.0, then inspect the reported dependency paths through machinepack-process and sails-generate. Determine which vulnerabilities remain and what change or documented decision would count as resolving this report; the issue currently provides no target file or test.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, node.js
Domain
backend, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.