Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

tile-extruder needs it's deps updated (security vulnerability) #35

Open
mreinstein opened this issue Jun 13, 2023 · 2 comments
Open

tile-extruder needs it's deps updated (security vulnerability) #35

mreinstein opened this issue Jun 13, 2023 · 2 comments

Comments

@mreinstein
Copy link

would you be open to a PR that updates the deps?

@mreinstein mreinstein changed the title tile-extruded needs it's deps updated (security vulnerability) tile-extruder needs it's deps updated (security vulnerability) Jun 13, 2023
@photonstorm
Copy link

Just curious where the security vulnerability actually is, given this is a 100% client-side script that runs as part of your asset workflow. It's worth updating the packages just to keep them current, though, of course.

@mreinstein
Copy link
Author

Just curious where the security vulnerability actually is

Right I'm not saying there is definitely a vulnerability that is exploitable; I haven't verified that.
Here is the warning I'm getting (via jimp it would seem):

Screenshot 2023-06-13 at 7 03 56 AM

given this is a 100% client-side script that runs as part of your asset workflow

That's the most likely use case, but it really depends on how one uses this module. :)

It's worth updating the packages just to keep them current, though, of course.

Yes, that's part of the purpose of this issue being opened; to see if this thing is still active and accepting PRs or if it's abandonware. I'm happy to try to help freshen deps but I don't want to spend time digging into changelogs and updating modules only to have it sit in a PR that languishes. Not saying that is a fault of tile-extruder, more endemic to the mausoleum -like state of the js module ecosystem.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants