• Recent
  • Tags
  • Unsolved
  • Solved
  • MagicMirror² Repository
  • Documentation
  • 3rd-Party-Modules
  • Donate
  • Discord
  • Register
  • Login
MagicMirror Forum
  • Recent
  • Tags
  • Unsolved
  • Solved
  • MagicMirror² Repository
  • Documentation
  • 3rd-Party-Modules
  • Donate
  • Discord
  • Register
  • Login
A New Chapter for MagicMirror: The Community Takes the Lead
Read the statement by Michael Teeuw here.

New Install From Raspbian Stretch

Scheduled Pinned Locked Moved Unsolved Troubleshooting
raspberry pi 3raspbian stretch
14 Posts 4 Posters 4.4k Views 4 Watching
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D Offline
    dazza120 @lavolp3
    last edited by Jan 21, 2019, 11:01 AM

    @lavolp3 understood thanks ill leave well alone now then thanks

    1 Reply Last reply Reply Quote 0
    • L Offline
      lavolp3 Module Developer @sebien0077
      last edited by Jan 21, 2019, 11:02 AM

      @sebien0077 better leave lodash alone is my suggestion. YOur mirror should work with this vulnerability as well.

      HOwever, you can of course try it out IF YOU DARE!!!
      Go on the presented link and do as suggested.

      npm install lodash@4.17.5
      

      (that’s what I would try)

      How to troubleshoot modules
      MMM-soccer v2, MMM-AVStock

      S 1 Reply Last reply Jan 21, 2019, 7:46 PM Reply Quote 0
      • S Offline
        sebien0077 @lavolp3
        last edited by Jan 21, 2019, 7:46 PM

        @lavolp3 said in New Install From Raspbian Stretch:

        npm install lodash@4.17.5

        Thx for your help. I just don’t like vulnerability :)
        i have try 4.17.5 and 4.17.11 … nothing work :(

        pi@raspberrypi:~/MagicMirror $ npm install lodash@4.17.5
        npm WARN acorn-jsx@5.0.1 requires a peer of acorn@^6.0.0 but none is installed. You must install peer dependencies yourself.
        
        + lodash@4.17.5
        updated 1 package and audited 4407 packages in 42.128s
        found 1 low severity vulnerability
          run `npm audit fix` to fix them, or `npm audit` for details
        pi@raspberrypi:~/MagicMirror $ npm audit fix
        npm WARN acorn-jsx@5.0.1 requires a peer of acorn@^6.0.0 but none is installed. You must install peer dependencies yourself.
        
        up to date in 31.654s
        fixed 0 of 1 vulnerability in 4407 scanned packages
          1 vulnerability required manual review and could not be updated
        pi@raspberrypi:~/MagicMirror $ npm audit
        
                               === npm audit security report ===
        
        ┌──────────────────────────────────────────────────────────────────────────────┐
        │                                Manual Review                                 │
        │            Some vulnerabilities require your attention to resolve            │
        │                                                                              │
        │         Visit https://go.npm.me/audit-guide for additional guidance          │
        └──────────────────────────────────────────────────────────────────────────────┘
        ┌───────────────┬──────────────────────────────────────────────────────────────┐
        │ Low           │ Prototype Pollution                                          │
        ├───────────────┼──────────────────────────────────────────────────────────────┤
        │ Package       │ lodash                                                       │
        ├───────────────┼──────────────────────────────────────────────────────────────┤
        │ Patched in    │ >=4.17.5                                                     │
        ├───────────────┼──────────────────────────────────────────────────────────────┤
        │ Dependency of │ express-ipfilter                                             │
        ├───────────────┼──────────────────────────────────────────────────────────────┤
        │ Path          │ express-ipfilter > lodash                                    │
        ├───────────────┼──────────────────────────────────────────────────────────────┤
        │ More info     │ https://nodesecurity.io/advisories/577                       │
        └───────────────┴──────────────────────────────────────────────────────────────┘
        found 1 low severity vulnerability in 4407 scanned packages
          1 vulnerability requires manual review. See the full report for details.
        pi@raspberrypi:~/MagicMirror $ npm install lodash@4.17.11
        npm WARN acorn-jsx@5.0.1 requires a peer of acorn@^6.0.0 but none is installed. You must install peer dependencies yourself.
        
        + lodash@4.17.11
        updated 1 package and audited 4407 packages in 39.671s
        found 1 low severity vulnerability
          run `npm audit fix` to fix them, or `npm audit` for details
        pi@raspberrypi:~/MagicMirror $ npm audit fix
        npm WARN acorn-jsx@5.0.1 requires a peer of acorn@^6.0.0 but none is installed. You must install peer dependencies yourself.
        
        up to date in 32.389s
        fixed 0 of 1 vulnerability in 4407 scanned packages
          1 vulnerability required manual review and could not be updated
        pi@raspberrypi:~/MagicMirror $ npm audit
        
                               === npm audit security report ===
        
        ┌──────────────────────────────────────────────────────────────────────────────┐
        │                                Manual Review                                 │
        │            Some vulnerabilities require your attention to resolve            │
        │                                                                              │
        │         Visit https://go.npm.me/audit-guide for additional guidance          │
        └──────────────────────────────────────────────────────────────────────────────┘
        ┌───────────────┬──────────────────────────────────────────────────────────────┐
        │ Low           │ Prototype Pollution                                          │
        ├───────────────┼──────────────────────────────────────────────────────────────┤
        │ Package       │ lodash                                                       │
        ├───────────────┼──────────────────────────────────────────────────────────────┤
        │ Patched in    │ >=4.17.5                                                     │
        ├───────────────┼──────────────────────────────────────────────────────────────┤
        │ Dependency of │ express-ipfilter                                             │
        ├───────────────┼──────────────────────────────────────────────────────────────┤
        │ Path          │ express-ipfilter > lodash                                    │
        ├───────────────┼──────────────────────────────────────────────────────────────┤
        │ More info     │ https://nodesecurity.io/advisories/577                       │
        └───────────────┴──────────────────────────────────────────────────────────────┘
        found 1 low severity vulnerability in 4407 scanned packages
          1 vulnerability requires manual review. See the full report for details.
        
        L 1 Reply Last reply Jan 21, 2019, 9:47 PM Reply Quote 0
        • S Offline
          sdetweil
          last edited by Jan 21, 2019, 7:49 PM

          as you will be the only user of the app (in your house, no public consumers, not open to internet)…

          the vulnerabilities really don’t matter…

          Sam

          How to add modules

          learning how to use browser developers window for css changes

          1 Reply Last reply Reply Quote 0
          • L Offline
            lavolp3 Module Developer @sebien0077
            last edited by Jan 21, 2019, 9:47 PM

            @sebien0077 Have you done a reboot? I hear they can do wonders!

            How to troubleshoot modules
            MMM-soccer v2, MMM-AVStock

            S 1 Reply Last reply Jan 21, 2019, 9:48 PM Reply Quote 0
            • S Offline
              sebien0077 @lavolp3
              last edited by Jan 21, 2019, 9:48 PM

              @lavolp3 yes, a lot of time ^^

              1 Reply Last reply Reply Quote 0
              • 1
              • 2
              • 2 / 2
              2 / 2
              • First post
                13/14
                Last post
              Enjoying MagicMirror? Please consider a donation!
              MagicMirror created by Michael Teeuw.
              Forum managed by Sam, technical setup by Karsten.
              This forum is using NodeBB as its core | Contributors
              Contact | Privacy Policy