-
Notifications
You must be signed in to change notification settings - Fork 131
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
npm README #100
Comments
The vulnerability was fixed in 1.0.4. I removed the note about the vulnerability in 98dc28c. It's still on npm because there was no new release since that commit. Only releases <= 1.0.3 are marked to be vulnerable and would be found by Does that answer your question? |
@pvorb Pardon me, how is it "no new release since that commit"? The latest release is 2.1.2 but the npm's README is outdated? |
That commit was after the 2.1.2 release. |
Got it. I thought the commit's somewhere between 1.0.4 and 2.1.2 🤣 |
Yeah, no worries. I had to revisit the commit history to make sure I wasn't wrong. |
The text 'XSS Vulnerability Detected' appears on the npmjs page for |
Yes |
hi ... may i ask what the xss vulnerability was due to, and what was the fix ? i cant seem to find the fix in the commits ... |
The NPM readme for this module states there is a XSS vulnerability, however this readme is different, and the
npm audit
shows no vulnerabilities.Was the issue resolved and just not republished to npm or is the issue still there but no longer in this readme?
The text was updated successfully, but these errors were encountered: