Skip to content

NPM found 1 high severity vulnerability (mongodb must be >=3.1.13) #283

@flaforgue

Description

@flaforgue

Hello,

First of all, thanks for your package which seems to be amazing ! I look forward to try it but I would like to warn you about this point : after the installation, NPM audit returns 1 high severity vulnerability. Here is the exact output :

                       === npm audit security report ===                        
                                                                                
                                                                                
                                 Manual Review                                  
             Some vulnerabilities require your attention to resolve             
                                                                                
          Visit https://go.npm.me/audit-guide for additional guidance           
                                                                                
                                                                                
  High            Denial of Service                                             
                                                                                
  Package         mongodb                                                       
                                                                                
  Patched in      >=3.1.13                                                      
                                                                                
  Dependency of   acl                                                           
                                                                                
  Path            acl > mongodb                                                 
                                                                                
  More info       https://nodesecurity.io/advisories/1203                       
                                                                                
found 1 high severity vulnerability in 879816 scanned packages
  1 vulnerability requires manual review. See the full report for details.

Do you think it would be a dependency hard to update ?

Have a nice day.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions