the `websocket-extensions` package is 6 years old, and downloaded 8 million times per week. 50% of the issues ever opened against it are people asking about a CVE that doesn't apply to it in the last 2 months
-
Show this thread
-
what actually happened here: there is a `websocket-extensions` package on npm, and in rubygems (I maintain both) a vuln was discovered in the npm one, and I found the ruby one had the same vuln. these were given *distinct* CVEs, GH security advisories. both released patches
1 reply 0 retweets 1 likeShow this thread -
the problem is that people are coming to the repo for the npm one and telling me that "synopsys black duck" is giving them an alert about the ruby one so either they're running the ruby one and coming to the wrong repo, or they're running the npm and getting bad alerts?
1 reply 0 retweets 2 likesShow this thread -
in any case people are coming to the repo for the npm one and going "please fix <CVE that relates to the ruby one>" *both* CVEs have been published and patched, there is nothing to be done here, both packages have *shipped fixes*
1 reply 0 retweets 2 likesShow this thread -
the confusion is possibly in the version numbers: the rubygems package is patched in 0.1.5, and the npm on in 0.1.4 so it's possible something is going "you're running websocket-driver 0.1.4 and that's bad"
1 reply 0 retweets 1 likeShow this thread -
that's still wrong because it's ignoring the ecosystem the package belongs to -- plenty of repos have packages with the same names, some related, some not
1 reply 0 retweets 4 likesShow this thread -
if you're running [npm/websocket-extensions@0.1.4] you should *not* be getting alerts about [rubygems/websocket-extensions] *at all* regardless of version
2 replies 0 retweets 4 likesShow this thread
See your critical mistake here was having users
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.