Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade package ip #2147

Closed
ramondeklein opened this issue Jun 4, 2024 · 5 comments
Closed

Upgrade package ip #2147

ramondeklein opened this issue Jun 4, 2024 · 5 comments
Assignees

Comments

@ramondeklein
Copy link
Contributor

ramondeklein commented Jun 4, 2024

NPM package auditing resulted in the following message:

└─ ip
   ├─ ID: 1097346
   ├─ Issue: ip SSRF improper categorization in isPublic
   ├─ URL: https://github.com/advisories/GHSA-2p57-rm9w-gvfp
   ├─ Severity: high
   ├─ Vulnerable Versions: <=2.0.1
   │ 
   ├─ Tree Versions
   │  └─ 2.0.1
   │ 
   └─ Dependents
      └─ web-app@workspace:.

The ip NPM package has a known security issue and needs to be upgraded. Once the package is upgraded then the line --ignore '1097346' can be removed from the ui.yaml workflow.

@ramondeklein
Copy link
Contributor Author

There is no updated version available yet.

@cesnietor
Copy link
Contributor

context: indutny/node-ip#150

@msummers42
Copy link

Came across this as a consumer of this package and a user of minio. It appears the upstream has archived the repo. We are considering moving to this fork https://github.com/eggjs/node-ip as we evaluate usage. It's tricky due to the sheer number of dependent projects.

@ramondeklein
Copy link
Contributor Author

@msummers42 Thanks for mentioning that https://github.com/indutny/node-ip is now archived. It looks like our repo isn't affected by the security issue, but relying on an archived package is never a good idea.

@cesnietor I think we should check what exactly depends on this package and how to fix that.

@pjuarezd
Copy link
Member

pjuarezd commented Aug 7, 2024

now that Operatoe console is deprecated we no longer need to upgrade the ip package

@pjuarezd pjuarezd closed this as completed Aug 7, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants