Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabilities in esm-seedrandom #11

Open
roirein opened this issue Dec 29, 2024 · 2 comments
Open

Vulnerabilities in esm-seedrandom #11

roirein opened this issue Dec 29, 2024 · 2 comments

Comments

@roirein
Copy link

roirein commented Dec 29, 2024

Hi,

For this package you use the library esm-seedrandom@3.0.5. the library depends on some packages that has vulnerabilities, you can refer the following link: shanewholloway/js-esm-seedrandom#7

can you please follow this issue and update accordingly? or in case those issues won't be handled use another library instead?

@Marko19907
Copy link
Owner

Hi,
Thanks for bringing this up!

The library esm-seedrandom is mainly a utility packed with lots of math functions. It does depend on the packages you mentioned there but these dependencies are strictly for testing and development purposes. They’re not included in the actual build or runtime of either esm-seedrandom or my library, so there’s no risk of these vulnerabilities affecting production usage.

That said, if the maintainer of esm-seedrandom releases a new version, I’ll make sure to release a new version of my library with the fix. I’ve been meaning to revisit this project for a while, so I appreciate the nudge!

Thanks again for keeping an eye on these details. Let me know if you have any other concerns, cheers!

@roirein
Copy link
Author

roirein commented Dec 30, 2024

Thank you very much!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants