Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Operational issues with umzug module #701

Open
Pavan1925 opened this issue Mar 18, 2025 · 5 comments
Open

Operational issues with umzug module #701

Pavan1925 opened this issue Mar 18, 2025 · 5 comments

Comments

@Pavan1925
Copy link

Team,

I wanted to point out that Black Duck is flagging operational vulnerabilities with umzug due to a lack of active development. Please update the dependency packages to the latest versions.

Any updates or plans for future development would be greatly appreciated.

Please take a look below report from blackduck and upgrade dependency modules accordingly.

Black Duck.pdf

@mmkal
Copy link
Contributor

mmkal commented Mar 18, 2025

Please share which dependencies you think are a problem directly on the issue as text or a screenshot. There have been some issue spam/phishing attempts recently I've seen.

Umzug is actively developed.

@Pavan1925
Copy link
Author

Hi @mmkal ,
Below are the screenshots as well as some of the operational issue factors:
Image

Image

These are some of issue but not all dependency packages with issues:

Image

Image

Image

Image

Image

@WikiRik
Copy link
Member

WikiRik commented Mar 18, 2025

Image

This seems to be a bug on their end, the last release date is correct but commits have been merged in the last 12 months.

Also; this is a bigger issue in the sector. Sometimes projects are feature complete and do not require regular releases. Therefore the risk is a false positive. Packages that do not have releases often might be more stable then packages that do

@WikiRik
Copy link
Member

WikiRik commented Mar 18, 2025

That being said; we can do a check on the current dependencies that we use and see if we can update to the latest version

@mmkal
Copy link
Contributor

mmkal commented Mar 18, 2025

I will take a look, but some of these might be coming from ts-command-line.

Recently I've been developing trpc-cli which I think would be a good fit. It does have dependencies but no transitive ones. I agree that this report looks inaccurate but I am in favour of moving off ts-command-line anyway.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants