cnodejs

cnodejs

Member Since 9 years ago

China

Experience Points
0
follower
Lessons Completed
0
follow
Best Reply Awards
11
repos
Activity
Oct
23
20 hours ago
Activity icon
created branch

fengmk2 in cnodejs/nodeclub create branch snyk-fix-c279e5341fdf3ad1df59bbad2d40f2f1

createdAt 13 hours ago
push

fengmk2 push cnodejs/nodeclub

fengmk2
fengmk2

fix: package.json to reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:

commit sha: fd2ee02b18ecc301ff05ace9c6ee05bd9c53b2b2

push time in 13 hours ago
pull request

snyk-bot pull request cnodejs/nodeclub

snyk-bot
snyk-bot

[Snyk] Security upgrade xss from 0.2.10 to 1.0.10

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-XSS-1584355
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: xss The new version differs by 173 commits.
  • 380a4ba publish: v1.0.10
  • 699acde fix: #239 stripCommentTag DoS attack
  • 9cbe2f1 Create SECURITY.md
  • bdd1b03 chore: fix nodejs.yml remove node-version 8.x
  • 3be6a07 chore: update devDependencies to latest version
  • 948dfb1 docs: update CI badge
  • 831a6a2 chore: github action nodejs.yml run test-cov instead of test
  • 0ba3cdb chore: remove .travis.yml
  • cdee88e chore: fix github action nodejs.yml
  • 624aba9 chore: add github action nodejs.yml
  • 901b771 style: reformat all source code by prettier
  • 0b15109 docs: update changelog
  • 3e153f5 fix: typings `onTag` options
  • 82cb63f docs: update changelog
  • a1d9b44 fix: typings IWhiteList allow any tag name
  • 005098b feat: Add `<strike>` to default whitelist
  • dcf1486 feat: Add `<audio crossorigin muted>`, `<video crossorigin muted playsinline poster>` to default whitelist
  • f4c0b29 Merge pull request #220 from daraz999/patch-1
  • 2f5dd55 fix: recover `<summary>` on the default whitelist
  • d94ac2a publish: v1.0.9
  • 4452638 chore: add package-lock.json to .ignore
  • cff16d9 chore: build dist
  • 730a0b5 Merge pull request #218 from TomAnthony/fix-whitespace-bypass
  • 6586f49 Merge pull request #216 from spacegaier/patch-1

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

Oct
22
1 day ago
started
started time in 1 day ago
started
started time in 1 day ago
started
started time in 1 day ago
Oct
20
3 days ago
started
started time in 3 days ago
Oct
19
4 days ago
started
started time in 4 days ago
started
started time in 4 days ago
started
started time in 4 days ago
Oct
18
5 days ago
started
started time in 5 days ago
Oct
14
1 week ago
started
started time in 1 week ago
Oct
13
1 week ago
started
started time in 1 week ago
Oct
12
1 week ago
started
started time in 1 week ago
started
started time in 1 week ago
Oct
11
1 week ago
Activity icon
fork

BsLeeha forked cnodejs/nodeclub

⚡ :baby_chick:Nodeclub 是使用 Node.js 和 MongoDB 开发的社区系统
BsLeeha MIT License Updated
fork time in 1 week ago
started
started time in 1 week ago
started
started time in 1 week ago
Oct
10
1 week ago
Activity icon
fork

Xheldon forked cnodejs/nodeclub

⚡ :baby_chick:Nodeclub 是使用 Node.js 和 MongoDB 开发的社区系统
Xheldon MIT License Updated
fork time in 1 week ago
Oct
9
2 weeks ago
started
started time in 2 weeks ago
Activity icon
fork

liclub forked cnodejs/nodeclub

⚡ :baby_chick:Nodeclub 是使用 Node.js 和 MongoDB 开发的社区系统
liclub MIT License Updated
fork time in 2 weeks ago
Oct
7
2 weeks ago
started
started time in 2 weeks ago
Oct
4
2 weeks ago
started
started time in 2 weeks ago
Oct
3
2 weeks ago
started
started time in 2 weeks ago
Sep
30
3 weeks ago
started
started time in 3 weeks ago
Sep
28
3 weeks ago
started
started time in 3 weeks ago
Sep
27
3 weeks ago
Activity icon
fork

suhank forked cnodejs/nodeclub

⚡ :baby_chick:Nodeclub 是使用 Node.js 和 MongoDB 开发的社区系统
suhank MIT License Updated
fork time in 3 weeks ago
Sep
25
4 weeks ago
Activity icon
issue

zfdream issue cnodejs/egg-cnode

zfdream
zfdream

运行nodeinstall --install-alinode ^3 报unknow version错误

运行nodeinstall --install-alinode ^3 的时候报这个错误。google了好几天了…… Error: Unknown version Dockerfile at _getNodeVersion (/usr/local/lib/node_modules/nodeinstall/lib/version.js:82:11) at getAlinodeVersion (/usr/local/lib/node_modules/nodeinstall/lib/version.js:21:12) at getAlinodeVersion.next (<anonymous>) at onFulfilled (/usr/local/lib/node_modules/nodeinstall/node_modules/co/index.js:65:19) at processTicksAndRejections (internal/process/task_queues.js:95:5)

Activity icon
issue

zfdream issue cnodejs/egg-cnode

zfdream
zfdream

运行nodeinstall --install-alinode ^3 报unknow version错误

运行nodeinstall --install-alinode ^3 的时候报这个错误。 Error: Unknown version Dockerfile at _getNodeVersion (/usr/local/lib/node_modules/nodeinstall/lib/version.js:82:11) at getAlinodeVersion (/usr/local/lib/node_modules/nodeinstall/lib/version.js:21:12) at getAlinodeVersion.next (<anonymous>) at onFulfilled (/usr/local/lib/node_modules/nodeinstall/node_modules/co/index.js:65:19) at processTicksAndRejections (internal/process/task_queues.js:95:5)

Sep
24
4 weeks ago
Activity icon
fork

ckvv forked cnodejs/egg-cnode

⚡ CNode 社区 Egg 版本
chenkai0520 MIT License Updated
fork time in 4 weeks ago
Previous