nodeSolidServer / nodeSolidServer/node-solid-server

NPM Audit - 17 high vulnerabilities for solid-server 5.8.5

未關閉
#1,821 4 則留言 1 個 reaction 已指派 0 人 在 GitHub 檢視

還沒有人認領這個 Issue。

主要語言
JavaScript
星號
1.8k
分支
308
PR 合併指標
30 天內沒有已合併 PR

描述

Hi,

I was wondering if you would be able to address the high vulnerabilities currently in the solid-server packages used?
If you run NPM Audit it says there are 17 high vulnerabilities and my university gets quite strict about me running code with high vulnerabilities.
I would be most grateful if you could take at look and perhaps at least reduce the list, if not eliminate it?

Kind regards.

貢獻指南

開啟貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

研究方向

首先對 solid-server 5.8.5 執行 NPM Audit,並檢查與 17 個高風險漏洞相關的套件相依性。判斷專案中可以處理哪些問題,然後重新執行稽核,以確認回報的高風險漏洞是否已減少或消除。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
javascript
領域
security
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
停滯
描述清晰度
需要釐清
新手友好度
25/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。