-
-
Notifications
You must be signed in to change notification settings - Fork 4.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
dependency CVE-2021-32708 in league/flysystem #27768
Comments
cc @nextcloud/security 👋 |
@icewind1991 I do not see this dependency being used anywhere in the Nextcloud code base. Can we remove it? PHPStorm shows only usages in our consumer file itself https://github.com/nextcloud/server/blob/master/lib/private/Files/Storage/Flysystem.php: Sourcegraph shows no usages in the org: |
@icewind1991 Ping |
This seems unused as per #27768 and may allow us to get rid of one more dependency. Signed-off-by: Lukas Reschke <lukas@statuscode.ch>
It is still present in 21.0.4 and also in 22.1.0 |
It is present in 22.2.0 as well. |
some applications will use it. |
the external app must ship the dependency itself - IMO. |
Yes, as per above the app should ship the dependency itself. Since the package is removed on our end I will also close this issue as the update is not needed anymore |
You should consider to include trivy into your pipeline for php/js dependency scan.
trivy fs --ignore-unfixed .
The text was updated successfully, but these errors were encountered: