Title: NPM audit reveals 9 moderate vulnerabilities in dependencies · Issue #1499 · nodegit/nodegit · GitHub
Open Graph Title: NPM audit reveals 9 moderate vulnerabilities in dependencies · Issue #1499 · nodegit/nodegit
X Title: NPM audit reveals 9 moderate vulnerabilities in dependencies · Issue #1499 · nodegit/nodegit
Description: There are 9 but 8 of them are from the deps of node-pre-gyp that depend on hoek annpm audit nodegit reveals: === npm audit security report === ┌──────────────────────────────────────────────────────────────────────────────┐ │ Manual Revi...
Open Graph Description: There are 9 but 8 of them are from the deps of node-pre-gyp that depend on hoek annpm audit nodegit reveals: === npm audit security report === ┌─────────────────────────────────────────────────────...
X Description: There are 9 but 8 of them are from the deps of node-pre-gyp that depend on hoek annpm audit nodegit reveals: === npm audit security report === ┌─────────────────────────────────────────────────────...
Opengraph URL: https://github.com/nodegit/nodegit/issues/1499
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"NPM audit reveals 9 moderate vulnerabilities in dependencies","articleBody":"There are 9 but 8 of them are from the deps of node-pre-gyp that depend on hoek an`npm audit nodegit` reveals:\r\n\r\n```\r\n \r\n === npm audit security report === \r\n \r\n\r\n\r\n\r\n┌──────────────────────────────────────────────────────────────────────────────┐\r\n│ Manual Review │\r\n│ Some vulnerabilities require your attention to resolve │\r\n│ │\r\n│ Visit https://go.npm.me/audit-guide for additional guidance │\r\n└──────────────────────────────────────────────────────────────────────────────┘\r\n┌───────────────┬──────────────────────────────────────────────────────────────┐\r\n│ moderate │ Prototype pollution │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Package │ hoek │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Dependency of │ nodegit │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Path │ nodegit \u003e node-pre-gyp \u003e hawk \u003e boom \u003e hoek │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ More info │ https://nodesecurity.io/advisories/566 │\r\n└───────────────┴──────────────────────────────────────────────────────────────┘\r\n┌───────────────┬──────────────────────────────────────────────────────────────┐\r\n│ moderate │ Prototype pollution │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Package │ hoek │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Dependency of │ nodegit │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Path │ nodegit \u003e node-pre-gyp \u003e hawk \u003e cryptiles \u003e boom \u003e hoek │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ More info │ https://nodesecurity.io/advisories/566 │\r\n└───────────────┴──────────────────────────────────────────────────────────────┘\r\n┌───────────────┬──────────────────────────────────────────────────────────────┐\r\n│ moderate │ Prototype pollution │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Package │ hoek │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Dependency of │ nodegit │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Path │ nodegit \u003e node-pre-gyp \u003e hawk \u003e hoek │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ More info │ https://nodesecurity.io/advisories/566 │\r\n└───────────────┴──────────────────────────────────────────────────────────────┘\r\n┌───────────────┬──────────────────────────────────────────────────────────────┐\r\n│ moderate │ Prototype pollution │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Package │ hoek │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Dependency of │ nodegit │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Path │ nodegit \u003e node-pre-gyp \u003e hawk \u003e sntp \u003e hoek │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ More info │ https://nodesecurity.io/advisories/566 │\r\n└───────────────┴──────────────────────────────────────────────────────────────┘\r\n┌───────────────┬──────────────────────────────────────────────────────────────┐\r\n│ moderate │ Prototype pollution │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Package │ hoek │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Dependency of │ nodegit │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Path │ nodegit \u003e node-pre-gyp \u003e request \u003e hawk \u003e boom \u003e hoek │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ More info │ https://nodesecurity.io/advisories/566 │\r\n└───────────────┴──────────────────────────────────────────────────────────────┘\r\n┌───────────────┬──────────────────────────────────────────────────────────────┐\r\n│ moderate │ Prototype pollution │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Package │ hoek │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Dependency of │ nodegit │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Path │ nodegit \u003e node-pre-gyp \u003e request \u003e hawk \u003e cryptiles \u003e boom \u003e │\r\n│ │ hoek │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ More info │ https://nodesecurity.io/advisories/566 │\r\n└───────────────┴──────────────────────────────────────────────────────────────┘\r\n┌───────────────┬──────────────────────────────────────────────────────────────┐\r\n│ moderate │ Prototype pollution │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Package │ hoek │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Dependency of │ nodegit │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Path │ nodegit \u003e node-pre-gyp \u003e request \u003e hawk \u003e hoek │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ More info │ https://nodesecurity.io/advisories/566 │\r\n└───────────────┴──────────────────────────────────────────────────────────────┘\r\n┌───────────────┬──────────────────────────────────────────────────────────────┐\r\n│ moderate │ Prototype pollution │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Package │ hoek │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Dependency of │ nodegit │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Path │ nodegit \u003e node-pre-gyp \u003e request \u003e hawk \u003e sntp \u003e hoek │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ More info │ https://nodesecurity.io/advisories/566 │\r\n└───────────────┴──────────────────────────────────────────────────────────────┘\r\n┌───────────────┬──────────────────────────────────────────────────────────────┐\r\n│ moderate │ Out-of-bounds Read │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Package │ stringstream │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Dependency of │ nodegit │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ Path │ nodegit \u003e node-pre-gyp \u003e request \u003e stringstream │\r\n├───────────────┼──────────────────────────────────────────────────────────────┤\r\n│ More info │ https://nodesecurity.io/advisories/664 │\r\n└───────────────┴──────────────────────────────────────────────────────────────┘\r\n\r\n[!] 9 vulnerabilities found - Packages audited: 532 (0 dev, 12 optional)\r\n Severity: 9 moderate\r\n\r\n```\r\n\r\nI _think_ this could be fixable by upgrading the version of node-pre-gyp in package.json as seen here https://github.com/mapbox/node-pre-gyp/issues/346","author":{"url":"https://github.com/juliedavila","@type":"Person","name":"juliedavila"},"datePublished":"2018-05-17T20:09:49.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":2},"url":"https://github.com/1499/nodegit/issues/1499"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:c0ced3f6-78ea-8c1c-8954-cd57bcc1a844 |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | 8872:3E033A:25C75C:32A5B2:6A5FAA4E |
| html-safe-nonce | 3520f266e6fd040d056e30da701dda2b4ccb490c79374ed3baabde5419553941 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiI4ODcyOjNFMDMzQToyNUM3NUM6MzJBNUIyOjZBNUZBQTRFIiwidmlzaXRvcl9pZCI6Ijc4ODg4MjY4OTcyMjY1NzM1OCIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9 |
| visitor-hmac | e72d0ca01ea508119b568f38b541fe9eebdb756a8a1b95e2887ccd443c929bb2 |
| hovercard-subject-tag | issue:324167839 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/nodegit/nodegit/1499/issue_layout |
| twitter:image | https://opengraph.githubassets.com/fb84e90e8f93c74cc519d16a6b884f3dc26ddedaee6e49a05ed55d1dd8bca0d4/nodegit/nodegit/issues/1499 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/fb84e90e8f93c74cc519d16a6b884f3dc26ddedaee6e49a05ed55d1dd8bca0d4/nodegit/nodegit/issues/1499 |
| og:image:alt | There are 9 but 8 of them are from the deps of node-pre-gyp that depend on hoek annpm audit nodegit reveals: === npm audit security report === ┌─────────────────────────────────────────────────────... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | juliedavila |
| hostname | github.com |
| expected-hostname | github.com |
| None | 9b835c054d57dfb6ce72ba8f0eb8f16f0370860631609eb10df818738c61c68d |
| turbo-cache-control | no-preview |
| go-import | github.com/nodegit/nodegit git https://github.com/nodegit/nodegit.git |
| octolytics-dimension-user_id | 657068 |
| octolytics-dimension-user_login | nodegit |
| octolytics-dimension-repository_id | 1383170 |
| octolytics-dimension-repository_nwo | nodegit/nodegit |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 1383170 |
| octolytics-dimension-repository_network_root_nwo | nodegit/nodegit |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 4df9bc0bde4bfd7cd95e75afdd7f103984ece3a1 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width