Read the statement by Michael Teeuw here.
New Install From Raspbian Stretch
-
Hi guys instead of me starting a new thread for the same thing can I jump in as it seems the last thing may have fixed OP’s issue, I have two vulnerabilities that are not fixing ate all 😢 can you help please I’ve tried the npm I lodash@latest but that doesn’t work
Manual Review │ │ Some vulnerabilities require your attention to resolve │ │ │ │ Visit https://go.npm.me/audit-guide for additional guidance │ └──────────────────────────────────────────────────────────────────────────────┘ ┌───────────────┬──────────────────────────────────────────────────────────────┐ │ Moderate │ Regular Expression Denial of Service │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Package │ underscore.string │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Patched in │ >=3.3.5 │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Dependency of │ fix │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Path │ fix > underscore.string │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ More info │ https://npmjs.com/advisories/745 │ └───────────────┴──────────────────────────────────────────────────────────────┘ ┌───────────────┬──────────────────────────────────────────────────────────────┐ │ Low │ Prototype Pollution │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Package │ lodash │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Patched in │ >=4.17.5 │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Dependency of │ express-ipfilter │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Path │ express-ipfilter > lodash │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ More info │ https://npmjs.com/advisories/577
-
Guys be careful with the npm vulnerabilities!
It’s not advisable to always fix all of them.
E.g. if a vulnerability wants to have a most recent version of an important dependency, fixing it might even break your working MM because MM can’t work with this new dependency.If you’re not completely sure what you’re doing then leave them.
They are not errors after all, your modules should work with these vulnerabilities as well. -
@lavolp3 understood thanks ill leave well alone now then thanks
-
@sebien0077 better leave lodash alone is my suggestion. YOur mirror should work with this vulnerability as well.
HOwever, you can of course try it out IF YOU DARE!!!
Go on the presented link and do as suggested.npm install lodash@4.17.5
(that’s what I would try)
-
@lavolp3 said in New Install From Raspbian Stretch:
npm install lodash@4.17.5
Thx for your help. I just don’t like vulnerability :)
i have try 4.17.5 and 4.17.11 … nothing work :(pi@raspberrypi:~/MagicMirror $ npm install lodash@4.17.5 npm WARN acorn-jsx@5.0.1 requires a peer of acorn@^6.0.0 but none is installed. You must install peer dependencies yourself. + lodash@4.17.5 updated 1 package and audited 4407 packages in 42.128s found 1 low severity vulnerability run `npm audit fix` to fix them, or `npm audit` for details pi@raspberrypi:~/MagicMirror $ npm audit fix npm WARN acorn-jsx@5.0.1 requires a peer of acorn@^6.0.0 but none is installed. You must install peer dependencies yourself. up to date in 31.654s fixed 0 of 1 vulnerability in 4407 scanned packages 1 vulnerability required manual review and could not be updated pi@raspberrypi:~/MagicMirror $ npm audit === npm audit security report === ┌──────────────────────────────────────────────────────────────────────────────┐ │ Manual Review │ │ Some vulnerabilities require your attention to resolve │ │ │ │ Visit https://go.npm.me/audit-guide for additional guidance │ └──────────────────────────────────────────────────────────────────────────────┘ ┌───────────────┬──────────────────────────────────────────────────────────────┐ │ Low │ Prototype Pollution │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Package │ lodash │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Patched in │ >=4.17.5 │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Dependency of │ express-ipfilter │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Path │ express-ipfilter > lodash │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ More info │ https://nodesecurity.io/advisories/577 │ └───────────────┴──────────────────────────────────────────────────────────────┘ found 1 low severity vulnerability in 4407 scanned packages 1 vulnerability requires manual review. See the full report for details. pi@raspberrypi:~/MagicMirror $ npm install lodash@4.17.11 npm WARN acorn-jsx@5.0.1 requires a peer of acorn@^6.0.0 but none is installed. You must install peer dependencies yourself. + lodash@4.17.11 updated 1 package and audited 4407 packages in 39.671s found 1 low severity vulnerability run `npm audit fix` to fix them, or `npm audit` for details pi@raspberrypi:~/MagicMirror $ npm audit fix npm WARN acorn-jsx@5.0.1 requires a peer of acorn@^6.0.0 but none is installed. You must install peer dependencies yourself. up to date in 32.389s fixed 0 of 1 vulnerability in 4407 scanned packages 1 vulnerability required manual review and could not be updated pi@raspberrypi:~/MagicMirror $ npm audit === npm audit security report === ┌──────────────────────────────────────────────────────────────────────────────┐ │ Manual Review │ │ Some vulnerabilities require your attention to resolve │ │ │ │ Visit https://go.npm.me/audit-guide for additional guidance │ └──────────────────────────────────────────────────────────────────────────────┘ ┌───────────────┬──────────────────────────────────────────────────────────────┐ │ Low │ Prototype Pollution │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Package │ lodash │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Patched in │ >=4.17.5 │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Dependency of │ express-ipfilter │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Path │ express-ipfilter > lodash │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ More info │ https://nodesecurity.io/advisories/577 │ └───────────────┴──────────────────────────────────────────────────────────────┘ found 1 low severity vulnerability in 4407 scanned packages 1 vulnerability requires manual review. See the full report for details.
-
as you will be the only user of the app (in your house, no public consumers, not open to internet)…
the vulnerabilities really don’t matter…
-
@sebien0077 Have you done a reboot? I hear they can do wonders!
-
@lavolp3 yes, a lot of time ^^