Conversation
|
I did a little bit more digging into the npm packages dependency tree of the app and it looks like the only package which depends on the problematic When I checked out their GH repo for more info, I found this CHANGELOG commit with some more info regarding the vulnerability: socketio/engine.io-client@df6a547. In it, they say that:
So it looks like we never really had this particular issue in this app! 😌 Should we close this PR then and consider the issue "resolved" or am I making some error in my thinking here? I'm not really a backend node.js dev and learned about the If we still wanted to upgrade However, as @mattwondra mentioned, that would mean having to deploy I'd personally prefer not upgrading to not cause any deploy issues since I've never worked on this app nor have I ever deployed it to its users so I'm not sure what all and where all I would need to look for issues. But if somebody more familiar with /cc @lezama @Automattic/lighthouse |
AFAIK the steps you took accurately identified the only dependency that would need to be upgraded ( However your screenshot was taken after the code in this PR has been applied, so those aren't the actual current package versions. If you The |


Should fix the security issue from p3btAN-1qI-p2.
Testing instructions
npm installandnpm start, openlocalhost:9000and https://hud-staging.happychat.io/ and try to chat with yourself.