cebe / cebe/php-openapi

Speccy uses dompurify with XSS vulnerability

Aperta
#157 5 commenti 0 reazioni 0 assegnatari Vedi su GitHub
overhead
Lingua principale
PHP
Stelle
500
Fork
99
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

Thought I would bring this up here as [Speccy ](https://github.com/wework/speccy) is a dead repo (last updated 3 years ago). It looks like Speccy is being used here and the latest version of Speccy is using an older version of [redoc](https://github.com/wework/speccy/blob/master/package-lock.json#L6443) which is using a [bad version](https://github.com/wework/speccy/blob/master/package-lock.json#L6450) of dompurify according to [snyk ](https://snyk.io/vuln/npm:dompurify).

Wondering what are thoughts around removing speccy from the repo?

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.