Security Concerns with Dependency Vulnerabilities in AdminLTE 4 #5714
Unanswered
Paulo-AndradeDev
asked this question in
Q&A
Replies: 1 comment
-
@Paulo-AndradeDev Without write access to the repo in question there is not much you can do Im affraid. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hey team,
Recently, while working on a project with AdminLTE 4.0.0-beta2, we encountered several security vulnerabilities flagged by GitHub's Dependabot. These include:
DOM Clobbering leading to potential XSS attacks via Rollup and Vite scripts
Prototype Pollution in dset
Backtracking regular expressions in path-to-regexp
These vulnerabilities were identified in the package-lock.json file. While we resolved the issue by updating:
it raises concerns about the security of dependencies we rely on.
Question: What steps can be taken to ensure ongoing security for AdminLTE 4 users, especially regarding dependency management? Would it be feasible to introduce a more frequent audit or automation for dependency updates to avoid potential future risks?
Thanks for your attention, and I look forward to hearing your thoughts!
Beta Was this translation helpful? Give feedback.
All reactions