Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Unmaintained? #11

Open
mikemaccana opened this issue Feb 21, 2019 · 1 comment
Open

Unmaintained? #11

mikemaccana opened this issue Feb 21, 2019 · 1 comment

Comments

@mikemaccana
Copy link

Installing this module:

npm WARN deprecated istanbul@0.4.5: This module is no longer maintained, try this instead:
npm WARN deprecated   npm i nyc
npm WARN deprecated Visit https://istanbul.js.org/integrations for other alternatives.
npm WARN deprecated to-iso-string@0.0.2: to-iso-string has been deprecated, use @segment/to-iso-string inste
ad.
npm WARN deprecated jade@0.26.3: Jade has been renamed to pug, please install the latest version of pug inst
ead of jade
npm WARN deprecated minimatch@0.3.0: Please update to minimatch 3.0.2 or higher to avoid a RegExp DoS issue 
npm WARN deprecated circular-json@0.3.3: CircularJSON is in maintenance only, flatted is its successor.
@mikemaccana
Copy link
Author

$ npm audit
                                                                                
                    === npm audit security report ===                        

# Run  npm install --save-dev karma@4.0.0  to resolve 13 vulnerabilities
SEMVER WARNING: Recommended action is a potentially breaking change

Low             Regular Expression Denial of Service                          

Package         debug                                                         

Dependency of   karma [dev]                                                   

Path            karma > socket.io > debug                                     

More info       https://npmjs.com/advisories/534                              




Low             Regular Expression Denial of Service                          

Package         debug                                                         

Dependency of   karma [dev]                                                   

Path            karma > socket.io > engine.io > debug                         

More info       https://npmjs.com/advisories/534                              




Low             Regular Expression Denial of Service                          

Package         debug                                                         

Dependency of   karma [dev]                                                   

Path            karma > socket.io > socket.io-adapter > debug                 

More info       https://npmjs.com/advisories/534                              




Low             Regular Expression Denial of Service                          

Package         debug                                                         

Dependency of   karma [dev]                                                   

Path            karma > socket.io > socket.io-client > debug                  

More info       https://npmjs.com/advisories/534                              




Low             Regular Expression Denial of Service                          

Package         debug                                                         

Dependency of   karma [dev]                                                   

Path            karma > socket.io > socket.io-client > engine.io-client >     
                debug                                                         

More info       https://npmjs.com/advisories/534                              




Low             Regular Expression Denial of Service                          

Package         debug                                                         

Dependency of   karma [dev]                                                   

Path            karma > socket.io > socket.io-adapter > socket.io-parser >    
                debug                                                         

More info       https://npmjs.com/advisories/534                              




Low             Regular Expression Denial of Service                          
                                                                                
Package         debug                                                         

Dependency of   karma [dev]                                                   

Path            karma > socket.io > socket.io-client > socket.io-parser >     
                debug                                                         

More info       https://npmjs.com/advisories/534                              




Low             Regular Expression Denial of Service                          

Package         debug                                                         

Dependency of   karma [dev]                                                   

Path            karma > socket.io > socket.io-parser > debug                  

More info       https://npmjs.com/advisories/534                              




Moderate        Prototype Pollution                                           

Package         lodash                                                        

Dependency of   karma [dev]                                                   

Path            karma > lodash                                                

More info       https://npmjs.com/advisories/782                              




Low             Prototype Pollution                                           

Package         lodash                                                        

Dependency of   karma [dev]                                                   

Path            karma > lodash                                                

More info       https://npmjs.com/advisories/577                              




Low             Regular Expression Denial of Service                          

Package         braces                                                        

Dependency of   karma [dev]                                                   

Path            karma > chokidar > anymatch > micromatch > braces             

More info       https://npmjs.com/advisories/786                              




Low             Regular Expression Denial of Service                          

Package         braces                                                        

Dependency of   karma [dev]                                                   

Path            karma > expand-braces > braces                                

More info       https://npmjs.com/advisories/786                              




High            Regular Expression Denial of Service                          

Package         parsejson                                                     

Dependency of   karma [dev]                                                   

Path            karma > socket.io > socket.io-client > engine.io-client >     
                parsejson                                                     
                                                                                
More info       https://npmjs.com/advisories/528                              



# Run  npm install --save-dev mocha@6.0.1  to resolve 3 vulnerabilities
SEMVER WARNING: Recommended action is a potentially breaking change

High            Regular Expression Denial of Service                          

Package         minimatch                                                     

Dependency of   mocha [dev]                                                   

Path            mocha > glob > minimatch                                      

More info       https://npmjs.com/advisories/118                              




Low             Regular Expression Denial of Service                          

Package         debug                                                         

Dependency of   mocha [dev]                                                   

Path            mocha > debug                                                 

More info       https://npmjs.com/advisories/534                              




Critical        Command Injection                                             

Package         growl                                                         

Dependency of   mocha [dev]                                                   

Path            mocha > growl                                                 

More info       https://npmjs.com/advisories/146                              



found 16 vulnerabilities (12 low, 1 moderate, 2 high, 1 critical) in 7357 scanned packages
16 vulnerabilities require semver-major dependency updates.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant