wolfiton
Github security concern related to phoenix 1.4 app
Hi everyone,
Today when i opened my email I got this from github:
> Security advisory GHSA-h9rv-jmmf-4pgx (moderate severity) affects 2 repositories:
> serialize-javascript (npm) used in 2 repositories
So i was wondering if the serialize-javascript is a default for phoenix 1.4 apps and what would be the best way to avoid this problem.
also i wanted to report this problem. The verion of phoenix used for this app is phoenix 1.4.11
The repo can be found here Blog API
Thanks in advance for any ideas or suggestions regarding this
Trending in Discussions
As the title says, please share what you’ve been up to with Elixir. Whether that’s been learning it, looking into it, making stuff with i...
New
@chrismccord : I just saw the Extract AGENTS.md from Phoenix.new into phx.new generator commit to the phoenix project.
My initial shotgu...
New
I was working on an Ecto migration and I needed a timestamp. So, for the nth time, I looked up the different data types for timestamps, a...
New
Just a general thread to post chat/news/info relating to AI/ML stuff that may be relevant for Nx now or in the future. Got anything to sh...
New
I just stumbled on a newly redesigned elixir-lang.org. :tada: It looks like @Software_Mansion did the work, and I think it is generally a...
New
There has been a thread to discuss the Stack Overflow Developer Survey on this forum every year since 2018, so here’s yet another one for...
New
Fly’s CEO posted this recently - Turn And Face The Strange · The Fly Blog
It says that Fly is going all-in on sprites, which is a worry ...
New
Other Trending Topics
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Hello everyone. After busy few months I am happy to announce v0.1.0 of Emerge & Solve.
They are GUI (Emerge) and State management (S...
New
Emily is an Elixir library that runs Nx computations on Apple’s MLX. Install it as the default Nx backend and Nx, defn, Axon, Nx.Serving,...
New
@hugobarauna and I (Alex Koutmos) have been hard at work on writing a book on Nerves that takes you from simply blinking LEDs to building...
New
There are three potential reasons for members of this forum to have a look at https://vutuv.de
You are tired or annoyed of LinkedIn.
Yo...
New
Latest Phoenix Threads
Chat & Discussions>Discussions
Latest on Elixir Forum
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #deployment
- #library
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #channels
- #elixirconf
- #exunit
- #discussion
- #code-sync
- #javascript
- #podcasts
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ecto-query
- #elixir-ls
- #phoenix_html
- #iex
- #blog-post
- #graphql
- #genstage
- #ai
- #elixirconf-us
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #api
- #forms
- #metaprogramming
- #hex
- #performance











First 6 of 6 Posts
kokolegorille
You probably need to upgrade your npm packages…
install this…
https://www.npmjs.com/package/npm-check-updates
then, from assets…
and add a babel.config.js file that looks like this
shanesveller
If you can give similar suggestions that use vanilla
npmcommands instead, you will help a much larger portion of readers at more skill/comfort/familiarity levels. Giving black-box advice has similar concerns tocurl | bash.kokolegorille
ok,
returns the list of outdated packages, then just update the versions of packages You want in packages.json and run npm install.
wolfiton
Thanks @kokolegorille for showing me that I only had to do an upgrade for my packages.json file.
I use
yarnand also ran previously before posting this thread this commandyarn upgrade. But it appears that this command will not ignore ranges.yarn upgrade --latestwill install the latest verisons without worrying about the constraints.Full list of yarn upgrade doc
jg-made
Hi I am having the same problem (getting
npm auditwarnings aboutserialize-javascriptwhich is depended on byuglifyjs-webpack-plugin)Latest version of the deprecated lib
uglifyjs-webpack-pluginis 2.2.0 and its package-lock.json specifies dependancy"serialize-javascript": "^1.7.0"which is installed by npm as"version": "1.9.1".I have tested this with a newly generated phoenix 1.4.9 project using
npm auditafter updatinguglifyjs-webpack-pluginto 2.2.0 and re-installing all node modules.What is most strange about this for me is that this
uglifyjs-webpack-pluginshouldn’t be appearing at all in our generated projects! See this PR Switch from uglifyjs-webpack-plugin to terser-webpack-plugin by sfusato · Pull Request #3189 · phoenixframework/phoenix · GitHub which was merged on 11 Dec 2018. Phoenix 1.4.9 was released on 4 July 2019.I don’t know why the generated projects are using the deprecated lib still but I fixed it manually by replicating the work done in that PR on my local project. It is very easy - only 3 lines in the whole project need changing. See here: Switch from uglifyjs-webpack-plugin to terser-webpack-plugin by sfusato · Pull Request #3189 · phoenixframework/phoenix · GitHub
BrightEyesDavid
For anyone who, for whatever reason, wants to stick with the versions specified by Phoenix, but update to the latest compatible minor/patch versions, I’ve found this to be a simple, no-stress approach:
package.jsonremains unchanged,package-lock.jsonis updated and can be committed to version control, and, as of today with Phoenix 1.4.16, npm audit finds 0 vulnerabilities.Here’s a Bash script to perform that for multiple web apps in an umbrella project, to be placed in and run from the umbrella project’s root directory.