Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Updating dependencies #48

Closed
4 tasks done
Sshetty2 opened this issue Mar 26, 2019 · 1 comment
Closed
4 tasks done

Updating dependencies #48

Sshetty2 opened this issue Mar 26, 2019 · 1 comment

Comments

@Sshetty2
Copy link

Sshetty2 commented Mar 26, 2019

Prerequisites

Please answer the following questions for yourself before submitting an issue.

  • I am running the latest version
  • I checked the documentation and found no answer
  • I checked to make sure that this issue has not already been filed
  • I'm reporting the issue to the correct repository (for multi-repository projects)

Expected Behavior

Please describe the behavior you are expecting

Updated project

Current Behavior

The project will work with the current dependencies

Failure Information (for bugs)

There are several outdated dependencies that may have vulnerabilities.

Please help provide information about the failure if this is a bug. If it is not a bug, please remove the rest of this template.

notably, Bootstrap and React-DOM need to be updated but several other decencies are out of date.

Additional Information

This product is absolutely awesome, but using any Node-based project with potentially vulnerable dependencies is a deal-breaker for me. I just got a virus on my computer that spawned from a vulnerability linked to Nodemon. It was really bad. Any major library could potentially be infected due to the striated nature of dependency trees, and thus, it is of the utmost important that dependencies are kept as up-to-date as possible; especially ones that have been marked as vulnerable by the registry.

Note: I have tried updating the dependencies but I broke my app and didn't know how to fix it.

Please help. I will definitely buy the pro version and recommend to colleagues as long as this is an updated product.

@einazare
Copy link
Contributor

Hello there, @Sshetty2 ,

Thank you for your interest in working with our product and for your concern about these issues.
You can go ahead and use the project as is. You shouldn't have any troubles.
At the moment we do not have time to update this product as we are stuck on some other projects.

We'll try and reschedule some of our other projects to make some time and update our older products and hopefully, in somewhat of a month we'll update these products.

Best,
Manu

@einazare einazare closed this as completed May 2, 2019
# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

No branches or pull requests

2 participants