Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

security violation - please update underscore package #10

Open
eran10 opened this issue Jan 18, 2022 · 3 comments
Open

security violation - please update underscore package #10

eran10 opened this issue Jan 18, 2022 · 3 comments

Comments

@eran10
Copy link

eran10 commented Jan 18, 2022

any change to update underscore package to 1.12.1 ? @BrunoBernardino
https://app.snyk.io/test/npm/visualcaptcha/0.1.3

@BrunoBernardino
Copy link
Contributor

BrunoBernardino commented Jan 18, 2022

@eran10 the _.template function isn't used, so that specific vulnerability doesn't apply here. That being said, I would not recommend you use this package anymore, at least not from this repo (maybe there's a more up-to-date fork?) since it hasn't been updated for many years, and it seems the new maintainer isn't planning to update it.

@eran10
Copy link
Author

eran10 commented Jan 19, 2022

thanks @BrunoBernardino , i like the idea of visualCaptcha, can you recommend any alternative package with a similar idea as this?

@BrunoBernardino
Copy link
Contributor

BrunoBernardino commented Jan 19, 2022

Perhaps https://www.hcaptcha.com/ or https://www.mtcaptcha.com/ though I have found no need to use captchas by default anymore, and if you detect a need for throttling, just start showing a simple question (rotated from a list of at least 10), like "what is five plus three?" or "what is the color of the sky?".

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants