Coder Social home page Coder Social logo

Comments (7)

dougwilson avatar dougwilson commented on May 13, 2024

I marked this as duplicate, so the conversation can be centralized here: #26 (comment)

from finalhandler.

XhmikosR avatar XhmikosR commented on May 13, 2024

NP, I didn't see anything relevant in the open issues. Maybe you should reopen #26 until a new version with the fix is published.

from finalhandler.

dougwilson avatar dougwilson commented on May 13, 2024

Publishing a new version won't resolve anything, as npm has set the affected version to all and so all new published versions will still be marked vulnerable. On top if that, it is unclear on what the issue is that should be fixed, as described in that issue.

The issue was closed when the change was merged and the open button is disabled.

from finalhandler.

XhmikosR avatar XhmikosR commented on May 13, 2024

The problem as far as I understand it is the CSP change patch, but a new version hasn't been released with the fix.

Admittedly, this hasn't been handled properly by whoever gets the npm reports out...

from finalhandler.

dougwilson avatar dougwilson commented on May 13, 2024

That was what I thought, but if that were the case the old versions of the module would not be marked as vulnerable as well. Since releasing a new version will still be marked as vulnerable anyway, I'm waiting to hear from them so I can definitely cut one that they will mark as not vulnerable.

from finalhandler.

XhmikosR avatar XhmikosR commented on May 13, 2024

All applies to all current versions not to future releases, as far as I understand it.

If you release a new version with the fix, ideally it should be only a patch release, then the people who review these things will mark only the old ones as vulnerable.

Again, this is how I get the whole situation myself. Personally, I would release a patch version with just this fix.

from finalhandler.

dougwilson avatar dougwilson commented on May 13, 2024

So if you're just going to argue here, I can't help you if you don't believe me.

from finalhandler.

Related Issues (16)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.