Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

1 low severity vulnerability #3823

Closed
zak100 opened this issue Dec 23, 2020 · 13 comments · Fixed by #4231
Closed

1 low severity vulnerability #3823

zak100 opened this issue Dec 23, 2020 · 13 comments · Fixed by #4231
Assignees
Labels
Investigate P3 Low severity bugs

Comments

@zak100
Copy link

zak100 commented Dec 23, 2020

Expected behavior

Don't know

Actual behavior

$ npm audit fix

up to date, audited 351 packages in 3s

44 packages are looking for funding
run npm fund for details

npm audit report

web3 *
Insecure Credential Storage - https://npmjs.com/advisories/877
No fix available
node_modules/web3

1 low severity vulnerability

Some issues need review, and may require choosing
a different dependency.

Steps to reproduce the behavior

1.$ npm install web3 (which gives this message but asks for audit fix)
2. npm audit fix (which again generates the problem message

Logs

no log file generated

Environment

Ubuntu 20.04 virtual machine running under ubuntu 18.04
[email protected] /home/osboxes/.nvm/versions/node/v15.4.0/lib/node_modules/npm
Laptop: amd64bit machine

@zak100
Copy link
Author

zak100 commented Dec 23, 2020

Hi,
Please guide me how to install web3? I am using "npm install web3 " but I am getting one severe vulnerability error.([email protected])
Zulfi.

@github-actions
Copy link

This issue has been automatically marked as stale because it has not had recent activity. It will be closed in 7 days if no further activity occurs. Thank you for your contributions. If you believe this was a mistake, please comment.

@github-actions github-actions bot added the Stale Has not received enough activity label Feb 22, 2021
@Zhenyazhd
Copy link

Hi,
Please guide me how to install web3? I am using "npm install web3 " but I am getting one severe vulnerability error.([email protected])
Zulfi.

Hi, did you solve this problem?? I have the same trouble. No matter what I do, I don't get to solve it...

@zak100
Copy link
Author

zak100 commented Mar 2, 2021 via email

@github-actions github-actions bot removed the Stale Has not received enough activity label Mar 2, 2021
@spacesailor24 spacesailor24 added Investigate P3 Low severity bugs labels Mar 5, 2021
@spacesailor24
Copy link
Contributor

Thank you for bringing this to our attention, we'll have to look at whether or not it's possible to update web3.js's dependencies to remove the warning

@zak100
Copy link
Author

zak100 commented Mar 5, 2021 via email

@Ramsolz666
Copy link

i also have this problem. Maybe i use the old version to operate

@zak100
Copy link
Author

zak100 commented Mar 24, 2021 via email

@github-actions
Copy link

This issue has been automatically marked as stale because it has not had recent activity. It will be closed in 7 days if no further activity occurs. Thank you for your contributions. If you believe this was a mistake, please comment.

@github-actions github-actions bot added the Stale Has not received enough activity label May 24, 2021
@DougZaoldyeck
Copy link

Any updates on this? I met the same problem when trying to run "npm install web3"

@github-actions github-actions bot removed the Stale Has not received enough activity label May 27, 2021
@Chinoiserie1
Copy link

Chinoiserie1 commented Jun 19, 2021

I have the same issue when I use npm install -g web3

web3 *
Insecure Credential Storage - https://npmjs.com/advisories/877
No fix available
node_modules/web3

1 low severity vulnerability

Some issues need review, and may require choosing
a different dependency.

@sonitaaaaa
Copy link

me too

npm audit report

web3 *
Insecure Credential Storage - https://npmjs.com/advisories/877
No fix available
node_modules/web3

1 low severity vulnerability

Some issues need review, and may require choosing
a different dependency.

@jdevcs jdevcs linked a pull request Aug 13, 2021 that will close this issue
10 tasks
@jdevcs
Copy link
Contributor

jdevcs commented Aug 13, 2021

This issue will be fixed with #4231 PR, and this issue is duplicate with #4225 so closing it.

@jdevcs jdevcs closed this as completed Aug 13, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Investigate P3 Low severity bugs
Projects
None yet
Development

Successfully merging a pull request may close this issue.

8 participants