Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update leaflet-omnivore st version to > 1.1.0 #585

Closed
philmikejones opened this issue Sep 10, 2018 · 3 comments
Closed

Update leaflet-omnivore st version to > 1.1.0 #585

philmikejones opened this issue Sep 10, 2018 · 3 comments

Comments

@philmikejones
Copy link

philmikejones commented Sep 10, 2018

When deploying a leaflet map through github pages, I am informed about a network vulnerability in the st package when using the leaflet-omnivore plugin.

I think the offending file is: https://github.com/rstudio/leaflet/blob/master/inst/htmlwidgets/lib/leaflet-omnivore/package.json

Please could you update the version of st used? I'm not sure if it's just a case of updating the reference in that file.
Thanks.

@schloerke
Copy link
Contributor

@philmikejones

This is a false positive message.

Leaflet-omnivore does not use the st package except for testing. It is not compiled in the distributed files which the leaflet R package uses. 'st' search results

I'm torn on fixing this as it is a leaflet-omnivore issue. Sure, I can change the offending line, but it will still cause issues down the road when omnivore is updated again.

Forwarding issue to leaflet-omnivore PR: mapbox/leaflet-omnivore#110

Linking to existing PR #575

-Barret

@philmikejones
Copy link
Author

Thanks, I thought it would be something like that. Thanks for looking into it

@schloerke
Copy link
Contributor

Closing as it looks like leaflet-omnivore is a ghost town. #575 fixed the issue

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants