wolfiton

wolfiton

Hi everyone,

Today when i opened my email I got this from github:

> Security advisory GHSA-h9rv-jmmf-4pgx (moderate severity) affects 2 repositories:
> serialize-javascript (npm) used in 2 repositories

So i was wondering if the serialize-javascript is a default for phoenix 1.4 apps and what would be the best way to avoid this problem.
also i wanted to report this problem. The verion of phoenix used for this app is phoenix 1.4.11

The repo can be found here Blog API
Thanks in advance for any ideas or suggestions regarding this

Showing Posts 1 to 6

kokolegorille

kokolegorille

You probably need to upgrade your npm packages…

install this…

https://www.npmjs.com/package/npm-check-updates

then, from assets…

$ cd assets
$ ncu -u

and add a babel.config.js file that looks like this

module.exports = api => {
  api.cache(true);

  const presets = [
    '@babel/preset-env',
  ]
  const plugins = [
  ]

  return {
    presets,
    plugins
  };
}
shanesveller

shanesveller

If you can give similar suggestions that use vanilla npm commands instead, you will help a much larger portion of readers at more skill/comfort/familiarity levels. Giving black-box advice has similar concerns to curl | bash.

kokolegorille

kokolegorille

ok,

$ mix phx.new -v
Phoenix v1.4.10
$ mix phx.new koko
$ cd koko/assets
$ npm outdated
Package                             Current  Wanted  Latest  Location
copy-webpack-plugin                   4.6.0   4.6.0   5.0.5  global
css-loader                            2.1.1   2.1.1   3.2.1  global
mini-css-extract-plugin               0.4.5   0.4.5   0.8.0  global
optimize-css-assets-webpack-plugin    4.0.3   4.0.3   5.0.3  global
uglifyjs-webpack-plugin               1.3.0   1.3.0   2.2.0  global
webpack                               4.4.0   4.4.0  4.41.2  global
webpack-cli                           2.1.5   2.1.5  3.3.10  global

returns the list of outdated packages, then just update the versions of packages You want in packages.json and run npm install.

wolfiton

wolfiton OP

Thanks @kokolegorille for showing me that I only had to do an upgrade for my packages.json file.
I use yarn and also ran previously before posting this thread this command yarn upgrade. But it appears that this command will not ignore ranges.
yarn upgrade --latest will install the latest verisons without worrying about the constraints.

Full list of yarn upgrade doc

jg-made

jg-made

Hi I am having the same problem (getting npm audit warnings about serialize-javascript which is depended on by uglifyjs-webpack-plugin)

Latest version of the deprecated lib uglifyjs-webpack-plugin is 2.2.0 and its package-lock.json specifies dependancy "serialize-javascript": "^1.7.0" which is installed by npm as "version": "1.9.1" .

I have tested this with a newly generated phoenix 1.4.9 project using npm audit after updating uglifyjs-webpack-plugin to 2.2.0 and re-installing all node modules.

What is most strange about this for me is that this uglifyjs-webpack-plugin shouldn’t be appearing at all in our generated projects! See this PR Switch from uglifyjs-webpack-plugin to terser-webpack-plugin by sfusato · Pull Request #3189 · phoenixframework/phoenix · GitHub which was merged on 11 Dec 2018. Phoenix 1.4.9 was released on 4 July 2019.

I don’t know why the generated projects are using the deprecated lib still but I fixed it manually by replicating the work done in that PR on my local project. It is very easy - only 3 lines in the whole project need changing. See here: Switch from uglifyjs-webpack-plugin to terser-webpack-plugin by sfusato · Pull Request #3189 · phoenixframework/phoenix · GitHub

BrightEyesDavid

BrightEyesDavid

For anyone who, for whatever reason, wants to stick with the versions specified by Phoenix, but update to the latest compatible minor/patch versions, I’ve found this to be a simple, no-stress approach:

cd "path/to/my_app_web/assets"
rm package-lock.json
rm -rf node_modules
npm install --silent --no-progress

package.json remains unchanged, package-lock.json is updated and can be committed to version control, and, as of today with Phoenix 1.4.16, npm audit finds 0 vulnerabilities.

Here’s a Bash script to perform that for multiple web apps in an umbrella project, to be placed in and run from the umbrella project’s root directory.

#!/usr/bin/env bash
set -o errexit

# Updates npm packages to latest available according to package.json.

web_apps_with_assets=(
	"my_app_web"
	"my_app_members_web"
	"my_app_admin_web"
)

bold=$(tput bold)
normal=$(tput sgr0)

# Change directory to that of this script
cd "${0%/*}"

for app in "${web_apps_with_assets[@]}"; do
	(
		echo -e "\n${bold}${app}${normal}"
		cd "apps/${app}/assets"
		rm package-lock.json
		rm -rf node_modules
		npm install --silent --no-progress
	)
done
— All posts loaded —

Where Next? Top

Trending in Discussions Top

AstonJ
As the title says, please share what you’ve been up to with Elixir. Whether that’s been learning it, looking into it, making stuff with i...
2977 94592 917
New
cblavier
Hey there, It’s been more than a year since we started using LiveView as our main UI library and building a whole library of UI componen...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
heathen
Quite interesting article Google brought me. Didn’t find any mentions about it here. What do you think in general? Would you use togethe...
New
mhanberg
Hi everyone! The first release candidate for the Expert language server project is now available! We’ve published a press release detai...
New
axelson
Hi there! :wave: @frigidcode and I (but mostly him) have been running an Elixir Book club, we’re almost done with Designing Elixir Syste...
New
budgie
A little off-topic, but I feel like people here have a good head on their shoulders. I used to be quite good at making software. Was luc...
New

Other Trending Topics Top

GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
marciok
Hi there! We created Gust: A task orchestrator inspired by Airflow. For those who have never heard about Aiflow, it’s a Python-based wor...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
georgeguimaraes
Just published claude-code-elixir, a plugin marketplace for Claude Code with Elixir support. These are the plugins I’ve been using for my...
New
Dmk
Xamal is a deployment tool for Elixir apps that deploys native releases to bare metal servers over SSH. It’s a port of GitHub - basecamp/...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews