Speccy uses dompurify with XSS vulnerability
- Langage dominant
- PHP
- Étoiles
- 500
- Forks
- 99
- Métriques de merge des PR
- Aucune PR mergée en 30 j
Description
Thought I would bring this up here as [Speccy ](https://github.com/wework/speccy) is a dead repo (last updated 3 years ago). It looks like Speccy is being used here and the latest version of Speccy is using an older version of [redoc](https://github.com/wework/speccy/blob/master/package-lock.json#L6443) which is using a [bad version](https://github.com/wework/speccy/blob/master/package-lock.json#L6450) of dompurify according to [snyk ](https://snyk.io/vuln/npm:dompurify).
Wondering what are thoughts around removing speccy from the repo?
Guide de contribution
Aucun guide de contribution indexé pour ce dépôt
Piste de recherche
Commencez par rechercher où Speccy est utilisé dans ce dépôt, puis examinez les entrées de Speccy dans package-lock.json aux lignes 6443 et 6450 ainsi que l’avis Snyk associé. Vérifiez si la suppression de Speccy affecte les workflows OpenAPI existants ; le travail est considéré comme terminé lorsque la dépendance vulnérable ne fait plus partie du dépôt sans interrompre ces workflows.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- javascript, php
- Domaine
- security, tooling
- Type d'issue
- Refactorisation
- Difficulté
- 4/5
- Temps estimé
- 3-5 jours
- Activité
- À l'abandon
- Clarté
- À clarifier
- Accessibilité débutants
- 25/100