Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

4043 Snyk Med, node-fetch #4137

Closed
wants to merge 2 commits into from
Closed

Conversation

rfultz
Copy link
Contributor

@rfultz rfultz commented Oct 20, 2020

Questions

Summary

  • Doesn't really resolve # 4043 so I'm not linking it. Yet.

This ticket upgrades draftail to the most recent version, but even it requires the draft-js version in this vulnerability.

Draftail powers our page admin interface so is inside the locked admin area.

Complications:

  • This ticket is about node-fetch
  • node-fetch is being used by a dependency of a dependency of draft-js, which is only being used by Draftail.
  • Draftail requires draft-js 0.10.5 and gives me a warning when I use a newer version (.5 is the last of 0.10 and 0.11.0 errs)
  • For us, this ticket requires an upgrade of Draftail, which doesn't exist

More complications:
We may need to look into a new editor as there hasn't been a Draftail update since August 2019. There's an issue from August 2020 asking whether the Draftail project is dead with no replies

dependency tree: [email protected][email protected][email protected][email protected]

Impacted areas of the application

Our site admin editor

Screenshots

Should be no visible changes

Related PRs

None

How to test


@rfultz rfultz added Please review Security: moderate Remediate within 60 days labels Oct 20, 2020
@rfultz rfultz self-assigned this Oct 20, 2020
@rfultz
Copy link
Contributor Author

rfultz commented Nov 3, 2020

Closing this because it doesn't really solve 4043. About to move #4043 to Blocked, too

@rfultz rfultz closed this Nov 3, 2020
@rfultz rfultz deleted the feature/4043-snyk-med-node-fetch- branch July 22, 2024 15:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Please review Security: moderate Remediate within 60 days
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant