-
Notifications
You must be signed in to change notification settings - Fork 459
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade package ip #2147
Comments
There is no updated version available yet. |
context: indutny/node-ip#150 |
Came across this as a consumer of this package and a user of minio. It appears the upstream has archived the repo. We are considering moving to this fork https://github.com/eggjs/node-ip as we evaluate usage. It's tricky due to the sheer number of dependent projects. |
@msummers42 Thanks for mentioning that https://github.com/indutny/node-ip is now archived. It looks like our repo isn't affected by the security issue, but relying on an archived package is never a good idea. @cesnietor I think we should check what exactly depends on this package and how to fix that. |
now that Operatoe console is deprecated we no longer need to upgrade the |
NPM package auditing resulted in the following message:
The ip NPM package has a known security issue and needs to be upgraded. Once the package is upgraded then the line
--ignore '1097346'
can be removed from theui.yaml
workflow.The text was updated successfully, but these errors were encountered: