Forum - Critical vulnerability in dependency of @exlibris/exl-cloudapp-base

  • This topic has 4 replies, 2 voices, and was last updated 3 months, 2 weeks ago by Systemlibarian University St.Gallen.
Viewing 5 posts - 1 through 5 (of 5 total)
  • Author
    Posts
  • #76227
    Systemlibarian University St.Gallen
    Participant

    Hello

    Part of my pre-release workflow is running ‘npm audit –audit-level=critical’, to make sure, my CloudApp wont be rejected.
    Now npm tells me, there are 4 critical vulnerabilities, because of ‘ loader-utils’ which is a dependecy of ‘@exlibris/exl-cloudapp-base’.

    I tried to add “loader-utils”: “^2.0.4” to my package.json, but it didn’t help.

    Can you please give me some advice, on how to solve this issue?
    I’m using:
    $ eca version
    v1.4.4
    $ node -v
    v13.14.0
    $ npm -v
    6.14.4

    Thank you and br
    Jonas

    #76228
    Mark Gobat
    Keymaster

    Hi Jonas…

    We are working on an update to the Cloud App SDK.

    Are you looking to publish an update to an existing Cloud App, or are you publishing a new Cloud App? We can get it published but may change our method of publication depending on your answer.

    Thank you.

    -mark

    #76230
    Systemlibarian University St.Gallen
    Participant

    Hi Mark

    Thank for your quick response!
    Currently I need to update an existing Cloud App (https://developers.exlibrisgroup.com/appcenter/print-slip-report/). I would greatly appreciate your help. How should I proceed?

    br
    Jonas

    #76233
    Mark Gobat
    Keymaster

    Hi Jonas…

    Go ahead and submit it for publication at your convenience. I’ll watch for it.

    Thank you.

    -mark

    #76235
    Systemlibarian University St.Gallen
    Participant

    Hi Mark

    Thank you very much. I just drafted a release on Github, so the Webhook should be run already.

    Best regards
    Jonas

Viewing 5 posts - 1 through 5 (of 5 total)
  • You must be logged in to reply to this topic.