Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

addressing accumulated security alerts on dependencies #59

Open
emiliom opened this issue Sep 7, 2021 · 4 comments
Open

addressing accumulated security alerts on dependencies #59

emiliom opened this issue Sep 7, 2021 · 4 comments

Comments

@emiliom
Copy link
Member

emiliom commented Sep 7, 2021

@BobTorgerson many dependency security alerts have accumulated on this software in the last 6 months, with a bunch of those labelled "high severity". Would you or @brucecrevensten have the bandwidth to see if any of them should be addressed?

Thanks!

@brucecrevensten
Copy link

Hi @emiliom thanks for putting this on our radar! We can definitely take a look. One thing to know, since this is a statically-deployed web app (i.e. not interactive and not managing user data on the server side), most of the security concerns tend to not apply. We'll put this in our roadmap for September.

@emiliom
Copy link
Member Author

emiliom commented Sep 9, 2021

Good point. I guess the main concern is then damage to users via the client web app code.
Thanks.

@brucecrevensten
Copy link

Totally valid! I did check take a look at the current warnings and I'm not seeing anything that raises my hackles about client security. Most were either server-side only, or development only (runs when the site is built). The one which could potentially impact client security isn't in use in our codebase.

I think we're good here for now, but we will want to look at doing a full update of dependencies at some point for this app. Let me know if this is OK for you -- we can keep this issue open until we do a refresh.

@emiliom
Copy link
Member Author

emiliom commented Sep 10, 2021

Sounds good to me. Thanks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants