NPM reports vulnerabilities upon installing Docusaurus.
node version: v11.10.1
npm verison: 6.9.0
OS: MacOS Mojave
Yes
(Write your steps here:)
The package should install without any security vulnerabilites,
| Moderate | Denial of Service |
|---------------------------------------------------------------------|----------------------------|
| Package | js-yaml |
| Patched in | >=3.13.0 |
| Dependency of | docusaurus [dev] |
| Path | docusaurus > cssnano > postcss-svgo > svgo > js-yaml |
| More info| https://npmjs.com/advisories/788 |
───────────────────────────────────────────
| High | Code Injection|
|---------------------------------------------------------------------|----------------------------|
| Patched in | >=3.13.1 |
| Dependency of | docusaurus [dev] |
| Path | docusaurus > cssnano > postcss-svgo > svgo > js-yaml |
| More info| https://npmjs.com/advisories/813 |
───────────────────────────────────────────
| Moderate | Regular Expression Denial of Service |
|---------------------------------------------------------------------|----------------------------|
| Package | underscore.string |
| Patched in | >=3.3.5 |
| Dependency of | docusaurus [dev] |
| Path | docusaurus > markdown-toc > remarkable > argparse > underscore.string |
| More info | https://npmjs.com/advisories/745 |
───────────────────────────────────────────
| Moderate | Regular Expression Denial of Service |
|---------- |----------------------------|
| Package | underscore.string |
| Patched in | >=3.3.5 |
| Dependency of | docusaurus [dev] |
| Path | docusaurus > remarkable > argparse > underscore.string |
| More info | https://npmjs.com/advisories/745 |
───────────────────────────────────────────
| Low | Regular Expression Denial of Service |
|-----|--------------------------------------|
| Package | debug |
| Patched in| >= 2.6.9 < 3.0.0 || >= 3.1.0 |
| Dependency of| docusaurus [dev] |
| Path| docusaurus > tcp-port-used > debug |
| More info| https://npmjs.com/advisories/534 |
───────────────────────────────────────────
All the above dependent packages have fixed their bugs. docusaurus need to upgrade the dependencies.
PR Welcome 😄
Hi @Shobhit1 , are you working on this?
@NishealJ doesn't seem like it, you are free to take it up!
sure @yangshun, i've raised a PR for the same Thanks !
I am not @NishealJ. Sorry for replying late. Feel free to pick it up.
Thanks
Most helpful comment
I am not @NishealJ. Sorry for replying late. Feel free to pick it up.
Thanks