nodeSolidServer / nodeSolidServer/node-solid-server
NPM Audit - 17 high vulnerabilities for solid-server 5.8.5
未关闭
还没有人认领这个 Issue。
- 主要语言
- JavaScript
- 星标
- 1.8k
- 派生
- 308
- PR 合并指标
- 30 天内没有已合并 PR
描述
Hi,
I was wondering if you would be able to address the high vulnerabilities currently in the solid-server packages used?
If you run NPM Audit it says there are 17 high vulnerabilities and my university gets quite strict about me running code with high vulnerabilities.
I would be most grateful if you could take at look and perhaps at least reduce the list, if not eliminate it?
Kind regards.
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
首先对 solid-server 5.8.5 运行 NPM Audit,并检查与 17 个高危漏洞相关的软件包依赖项。确定项目中可以处理哪些问题,然后重新运行审计,以验证报告的高危漏洞是否已减少或消除。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- javascript
- 领域
- security
- Issue 类型
- 缺陷
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 停滞
- 描述清晰度
- 需要澄清
- 新手友好度
- 25/100