Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

@types/swagger-express-mw vulnerabilities #31

Open
sandhuharjodh opened this issue Sep 13, 2019 · 3 comments
Open

@types/swagger-express-mw vulnerabilities #31

sandhuharjodh opened this issue Sep 13, 2019 · 3 comments

Comments

@sandhuharjodh
Copy link

Anyone have an idea when these vulnerabilities can be fixed for package???

Introduced through: [email protected][email protected][email protected]
Introduced through: [email protected][email protected][email protected][email protected]
Introduced through: [email protected][email protected][email protected][email protected][email protected]

Introduced through: [email protected][email protected][email protected][email protected][email protected][email protected]
Introduced through: [email protected][email protected][email protected][email protected][email protected][email protected]
Introduced through: [email protected][email protected][email protected][email protected][email protected][email protected][email protected]

Introduced through: [email protected][email protected][email protected][email protected][email protected][email protected][email protected]
Introduced through: [email protected][email protected][email protected][email protected][email protected][email protected][email protected][email protected]
Introduced through: [email protected][email protected][email protected][email protected][email protected][email protected][email protected][email protected]

@danielwhatmuff
Copy link

+1

@sandhuharjodh
Copy link
Author

Any updates?

@plaa
Copy link

plaa commented May 6, 2020

As this package and swagger-node-runner seem to be abandoned, I created forked versions of swagger-express-mw, swapper-node-runner and bagpipes which fix all but one minor vulnerability (blocked by #137). I don't plan on maintaining them other than possible occasional lib updates.

You can use patched libs you need by:

"swagger-express-mw": "Vincit/swagger-express#026b9527ebb8402db20bc479ed21e4047f1c45ba",
"swagger-node-runner": "Vincit/swagger-node-runner#427d0a4c43599de4aa03e2b3a359847b1b75cf84"
"bagpipes": "Vincit/bagpipes#b2eb059ba6f87c9185a83646fe5bac48288ccea4",

(I always recommend using commit-id locked versions when referring directly to Github repositories.)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants