Skip to content

Update *express* dependency #1

Description

@pdehaan

The specified version of express@~4.1.2 has a couple of known issues w/ the qs and send modules, see:
https://nodesecurity.io/advisories/qs_dos_memory_exhaustion
https://nodesecurity.io/advisories/qs_dos_extended_event_loop_blocking
https://nodesecurity.io/advisories/send-directory-traversal

Or here's the full list of outdated modules:

$ git clone https://github.com/saschagehlich/node-seo.git .

$ npm install

$ npm shrinkwrap --dev
wrote npm-shrinkwrap.json

$ # sudo npm i nsp -g
$ nsp audit-shrinkwrap
Name  Installed   Patched  Vulnerable Dependency
send    0.3.0    >= 0.8.4  seo > express
qs      0.6.6     >= 1.x   seo > express
qs      0.6.6     >= 1.x   seo > supertest > superagent

$ npm outdated --depth 0
Package     Current  Wanted  Latest  Location
express       4.1.2   4.1.2   4.9.0  express
mocha        1.18.2  1.18.2  1.21.4  mocha
should        3.3.2   3.3.2   4.0.4  should
supertest    0.12.1  0.12.1  0.13.0  supertest
underscore    1.6.0   1.6.0   1.7.0  underscore

$ travis-lint # http://lint.travis-ci.org/saschagehlich/node-seo

$ # sudo npm i pjv -g
$ pjv -wr
{ valid: true,
  warnings: [ 'Missing recommended field: contributors' ],
  recommendations: [ 'Missing optional field: engines' ] }

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions