cloudinary / cloudinary/cloudinary-react-native

Vulnerabilities in Package

未关闭
#25 5 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
TypeScript
星标
28
派生
21
PR 合并指标
30 天内没有已合并 PR

描述

## Bug report for Cloudinary React Native SDK
Before proceeding, please update to latest version and test if the issue persists

## Describe the bug in a sentence or two.

During install process, npm says there are 18 vulnerabilities (14 moderate, 4 high). It installs just fine, but I am a little less than thrilled to be adding it to my project.

## Issue Type (Can be multiple)
[ ] Build - Can’t install or import the SDK
[ ] Performance - Performance issues
[ ] Behaviour - Functions aren’t working as expected (Such as generate URL)
[ ] Documentation - Inconsistency between the docs and behaviour
[x] Other (Specify) - Security

## Steps to reproduce
Install package using npm

## Error screenshots or Stack Trace (if applicable)
![cloudinary install security issues](https://github.com/cloudinary/cloudinary-react-native/assets/79173587/2408958f-fb1c-4124-ba4b-380e7cbb6bdf)

## Build/Dependency management
[x] Cocoa-Pods
[ ] Carthage
[ ] Manual import
[x] Other (Specify) - npm

## Is the issue reproducible only on a specific device?
[x] No - not tested, but given the circumstances, I wouldn't think so
[ ] Yes (specify device model + iOS/Android version)

## Versions and Libraries (fill in the version numbers)
React Native Cloudinary SDK version - 1.0.0
OSX (on the dev environment) - 14.5

Repository
If possible, please provide a link to a reproducible repository that showcases the problem

贡献指南

打开贡献指南

调研方向

首先使用 npm 安装版本 1.0.0,并审计依赖树,以确定哪些软件包导致了报告中的 18 个漏洞。确认这些发现是否会影响运行时依赖项,然后将“解决适用的漏洞且不破坏 React Native SDK”定义为完成标准。

由索引模型根据 Issue 内容生成。

评估

技术栈
react-native, typescript
领域
mobile-dev, security
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
停滞
描述清晰度
需要澄清
新手友好度
25/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。