kevva / kevva/bin-build

vulnerability error

Open
#13 3 comments 10 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
39
Forks
15
PR merge metrics
No merged PRs in 30d

Description

Hi, there are multiple vulnerabilities with some widely-used versions of your package.
Can they be addressed and back-ported?

```
npx: installed 115 in 9.19s
(+) 1 vulnerability found
┌────────────┬────────────────────────────────────────────────────────────────────┐
│ │ Memory Exposure │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Name │ tunnel-agent │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ CVSS │ 5 (Medium) │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Installed │ 0.4.3 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Vulnerable │ <0.6.0 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Patched │ >=0.6.0 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Path │ nuxt-imagemin@0.1.2 > imagemin-webpack-plugin@2.1.1 > │
│ │ imagemin-optipng@5.2.1 > optipng-bin@3.1.4 > bin-build@2.2.0 > │
│ │ download@4.4.3 > caw@1.2.0 > tunnel-agent@0.4.3 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ More Info │ https://nodesecurity.io/advisories/598 │
└────────────┴────────────────────────────────────────────────────────────────────┘

┌────────────┬────────────────────────────────────────────────────────────────────┐
│ │ Prototype Pollution │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Name │ deep-extend │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ CVSS │ 2 (Low) │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Installed │ 0.5.1 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Vulnerable │ <6.5.2 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Patched │ >=6.5.2 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Path │ wemake-vue-demo@0.1.0 > nuxt-imagemin@0.1.2 > │
│ │ imagemin-webpack-plugin@2.1.1 > imagemin-optipng@5.2.1 > │
│ │ optipng-bin@3.1.4 > bin-build@2.2.0 > download@4.4.3 > caw@1.2.0 > │
│ │ get-proxy@1.1.0 > rc@1.2.7 > deep-extend@0.5.1 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ More Info │ https://nodesecurity.io/advisories/594 │
└────────────┴────────────────────────────────────────────────────────────────────┘

┌────────────┬────────────────────────────────────────────────────────────────────┐
│ │ Prototype Pollution │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Name │ deep-extend │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ CVSS │ 2 (Low) │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Installed │ 0.5.1 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Vulnerable │ All │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Patched │ None ���
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Path │ wemake-vue-demo@0.1.0 > nuxt-imagemin@0.1.2 > │
│ │ imagemin-webpack-plugin@2.1.1 > imagemin-optipng@5.2.1 > │
│ │ optipng-bin@3.1.4 > bin-build@2.2.0 > download@4.4.3 > caw@1.2.0 > │
│ │ get-proxy@1.1.0 > rc@1.2.7 > deep-extend@0.5.1 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ More Info │ https://nodesecurity.io/advisories/612 │
└────────────┴────────────────────────────────────────────────────────────────────┘

┌────────────┬────────────────────────────────────────────────────────────────────┐
│ │ Prototype Pollution │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Name │ deep-extend │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ CVSS │ 2 (Low) │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Installed │ 0.5.1 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Vulnerable │ <1.0.1 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Patched │ >=1.0.1 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Path │ wemake-vue-demo@0.1.0 > nuxt-imagemin@0.1.2 > │
│ │ imagemin-webpack-plugin@2.1.1 > imagemin-optipng@5.2.1 > │
│ │ optipng-bin@3.1.4 > bin-build@2.2.0 > download@4.4.3 > caw@1.2.0 > │
│ │ get-proxy@1.1.0 > rc@1.2.7 > deep-extend@0.5.1 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ More Info │ https://nodesecurity.io/advisories/611 │
└────────────┴─���──────────────────────────────────────────────────────────────────┘

┌────────────┬────────────────────────────────────────────────────────────────────┐
│ │ Memory Exposure │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Name │ tunnel-agent │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ CVSS │ 5 (Medium) │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Installed │ 0.4.3 │
├─────���──────┼────────────────────────────────────────────────────────────────────┤
│ Vulnerable │ <0.6.0 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Patched │ >=0.6.0 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Path │ wemake-vue-demo@0.1.0 > nuxt-imagemin@0.1.2 > │
│ │ imagemin-webpack-plugin@2.1.1 > imagemin-optipng@5.2.1 > │
│ │ optipng-bin@3.1.4 > bin-build@2.2.0 > download@4.4.3 > caw@1.2.0 > │
│ │ tunnel-agent@0.4.3 │
├────────────┼───────────────────────────���────────────────────────────────────────┤
│ More Info │ https://nodesecurity.io/advisories/598 │
└────────────┴────────────────────────────────────────────────────────────────────┘
```

Related: https://github.com/wemake-services/nuxt-imagemin/issues/2
Related: https://github.com/Klathmon/imagemin-webpack-plugin/issues/60
Related: https://github.com/imagemin/optipng-bin/issues/98

Contributor guide

No contributing guide indexed for this repository

Research direction

No source files or tests are mentioned. Start by tracing the listed dependency paths for tunnel-agent and deep-extend, then determine how the reported versions are selected and whether patched versions can be used. Done means the reported vulnerabilities are addressed and the dependency scan no longer flags these paths.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, nodejs
Domain
build-system, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.