Skip to content

Documenting audit failure in ini package #896

@DrewWarrenTIY

Description

@DrewWarrenTIY

Currently when the Travis CI Pipeline runs there are 100 fo the same vulnerability detected that looks like this:

┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Low           │ Prototype Pollution                                          │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ ini                                                          │
├───────────────┼──────────────────────���───────────────────────────────────────┤
│ Dependency of │ webpack-dev-server [dev]                                     │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ webpack-dev-server > chokidar > fsevents > node-pre-gyp > rc │
│               │ > ini                                                        │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://nodesecurity.io/advisories/1589                      │
└───────────────┴──────────────────────────────────────────────────────────────┘

There is currently a PR submitted for the rc package here:

dominictarr/rc#121

Since the assessment is low and there is an upstream PR open, we are comfortable 'ignoring' this for now. Hopefully it is resolved by the maintainer of rc soon.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions