Speccy uses dompurify with XSS vulnerability
Aperta
overhead
- Lingua principale
- PHP
- Stelle
- 500
- Fork
- 99
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Descrizione
Thought I would bring this up here as [Speccy ](https://github.com/wework/speccy) is a dead repo (last updated 3 years ago). It looks like Speccy is being used here and the latest version of Speccy is using an older version of [redoc](https://github.com/wework/speccy/blob/master/package-lock.json#L6443) which is using a [bad version](https://github.com/wework/speccy/blob/master/package-lock.json#L6450) of dompurify according to [snyk ](https://snyk.io/vuln/npm:dompurify).
Wondering what are thoughts around removing speccy from the repo?
Guida per i contributori
Nessuna guida per i contributori indicizzata per questo repository
Valutazione
Questa issue non è ancora stata valutata.