Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security: cryptiles #482

Open
y-lohse opened this issue Mar 19, 2019 · 0 comments
Open

Security: cryptiles #482

y-lohse opened this issue Mar 19, 2019 · 0 comments
Labels

Comments

@y-lohse
Copy link
Contributor

y-lohse commented Mar 19, 2019

We currently have a security alert for cryptileshttps://github.com/cozy/cozy-contacts/network/alert/yarn.lock/cryptiles/open

yarn why cryptiles

"cozy-bar#cozy-client-js#pouchdb#request#hawk" depends on it
 - Hoisted from "cozy-bar#cozy-client-js#pouchdb#request#hawk#cryptiles"

This is the same vulnerability than on most of our projects, coming from an old pouchdb version. It only affects the node eversion, so the shipped web app is not at risk.

This will eventually be solved by upgrading pouchdb in cozy-client-js.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant