Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

3 high severity vulnerabilities #422

Closed
QimatLuo opened this issue Aug 27, 2022 · 3 comments · Fixed by #431
Closed

3 high severity vulnerabilities #422

QimatLuo opened this issue Aug 27, 2022 · 3 comments · Fixed by #431
Labels
3rd party Issue is linked to or blocked by 3rd party dependencies DONE Implementation is done, but not yet merged into master

Comments

@QimatLuo
Copy link

npm i @nut-tree/[email protected]
Then we can see vulnerabilities dependencies.
Better to solve it.

image

@s1hofmann s1hofmann added the 3rd party Issue is linked to or blocked by 3rd party dependencies label Aug 27, 2022
@s1hofmann
Copy link
Member

Hi @QimatLuo 👋

while we're waiting for an upstream fix I published a short advisory how users can mitigate these vulnerabilities in the meantime: https://nutjs.dev/blog/jimp-security-advisory

@QimatLuo
Copy link
Author

Works for me.
Should I close this issue now? or just wait for the upstream fix then close this issue?

@s1hofmann
Copy link
Member

You can keep it open, I'll close it once it's fixed upstream

@s1hofmann s1hofmann added the DONE Implementation is done, but not yet merged into master label Sep 15, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
3rd party Issue is linked to or blocked by 3rd party dependencies DONE Implementation is done, but not yet merged into master
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants