Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Unsafe dependency #55

Closed
abdelaz3r opened this issue Apr 28, 2022 · 1 comment
Closed

Unsafe dependency #55

abdelaz3r opened this issue Apr 28, 2022 · 1 comment
Labels
bug good-first-issue Good for newbies / that are still green ;)

Comments

@abdelaz3r
Copy link

Hi,

One of the dependency is not safe according to mix deps.audit. Here is the full output of the command :

Name: sweet_xml
Version: 0.6.6
Lockfile: /home/runner/work/app/app/mix.lock
CVE: 2019-15160
URL: https://github.com/kbrw/sweet_xml/issues/71
Title: Inline DTD allows XML bomb attack
Patched versions: >= 0.7.0

Vulnerabilities found!

Would it be possible to update that dependency and create a current release ?

@szymon-jez
Copy link
Member

The dependency is now in line with Patched versions: >= 0.7.0 on develop.
https://github.com/socialpaymentsbv/ex_phone_number/blob/acf3c36090bb3d07b39b95cc4abf8f6d44e75d30/mix.lock#L23

master still has 0.6 so the solution could be to port 86a253c to master as releasing current develop is not possible because it is in a WIP state (see #43).

Help in doing the port (PR) is welcome.

@szymon-jez szymon-jez added bug good-first-issue Good for newbies / that are still green ;) labels Apr 29, 2022
josemrb added a commit that referenced this issue Jun 17, 2022
@josemrb josemrb closed this as completed Jun 17, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug good-first-issue Good for newbies / that are still green ;)
Projects
None yet
Development

No branches or pull requests

3 participants