10000 Security Vulnerabilities Detected by Dependabot (postgreSQL/html/jquery.js) · Issue #161 · EDIorg/ecocomDP · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

Security Vulnerabilities Detected by Dependabot (postgreSQL/html/jquery.js) #161

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
clnsmth opened this issue May 19, 2025 · 3 comments
Open

Comments

@clnsmth
Copy link
Contributor
clnsmth commented May 19, 2025

Hi @mobb,

Dependabot has flagged the ecocomDP repository for potential security vulnerabilities related to the file postgreSQL/html/jquery.js. This file appears to have been originally committed by you.

There are a couple ways we could address these reported vulnerabilities:

  1. Update the files: Investigate the specific vulnerabilities reported by Dependabot and update the affected files (or their dependencies) to resolve these issues. This would preserve any potential utility of this content.
  2. Remove the files: If the content in these files is no longer deemed necessary or if updating them is not feasible, we could remove them from the repository entirely.

What are your thoughts on how we should proceed with this?

Thanks for your input!

@mobb
Copy link
Contributor
mobb commented May 20, 2025

I don't think updating is worth the time. It (along with the HTML) was created by the program that generated ERD (in this case, schemaSpy), and no one uses the html view. We do use the SVG output, but have been editing that manually.

I'll drop the text of this file but leave a note there that says it that if someone wants to regenerate the html and svg, they should do so with a current version of schemaSpy or some other ERD generator.

@mobb mobb closed this as completed May 20, 2025
@clnsmth
Copy link
Contributor Author
clnsmth commented May 21, 2025

Thanks @mobb!

@clnsmth
Copy link
Contributor Author
clnsmth commented May 27, 2025

@mobb, it looks like Dependabot isn't entirely happy with this. Even though you've commented out the code, Dependabot still flags it. One option might be to update the version number in jquery.js to the one it recommends.

I can do this if you'd like.

@clnsmth clnsmth reopened this May 27, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants
0