This profile exists so I can contribute to projects hosted on GitHub.
All my new projects are stored on https://git.mnau.xyz.
Discord Entertainment bot written in NodeJS
License: GNU Affero General Public License v3.0
This profile exists so I can contribute to projects hosted on GitHub.
All my new projects are stored on https://git.mnau.xyz.
Safer version of eval()
path: /JustAPotato/node_modules/safe-eval/package.json
Library home page: https://registry.npmjs.org/safe-eval/-/safe-eval-0.3.0.tgz
Dependency Hierarchy:
The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized user input can access the entire standard library and effectively break out of the sandbox.
Publish Date: 2018-06-07
URL: CVE-2017-16088
Base Score Metrics:
Type: Upgrade version
Origin: https://nodesecurity.io/advisories/337
Release Date: 2017-08-30
Fix Resolution: No direct patch for this package is available, due to restrictions inherent in the node platform. Executing untrusted user input as code is rarely safe, and the use of packages like this are always going to carry some degree of risk.
At this time, it is not recommended to use this package.
A safer solution for executing untrusted code is to run the code using OS level containerization, such as docker.
Step up your Open Source Security Game with WhiteSource here
General purpose node utilities
path: /JustAPotato/node_modules/hoek/package.json
Library home page: http://registry.npmjs.org/hoek/-/hoek-2.16.3.tgz
Dependency Hierarchy:
hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' and 'applyToDefaults' functions, which allows a malicious user to modify the prototype of "Object" via proto, causing the addition or modification of an existing property that will exist on all objects.
Publish Date: 2018-03-30
URL: CVE-2018-3728
Base Score Metrics:
Type: Change files
Origin: hapijs/hoek@623667e
Release Date: 2018-02-15
Fix Resolution: Replace or update the following files: index.js, index.js
Step up your Open Source Security Game with WhiteSource here
Lodash modular utilities.
path: /JustAPotato/node_modules/lodash/package.json
Library home page: https://registry.npmjs.org/lodash/-/lodash-4.17.10.tgz
Dependency Hierarchy:
In the node_module "lodash" before version 4.17.11 the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of the Object prototype. These properties will be present on all objects.
Publish Date: 2018-11-25
URL: WS-2018-0210
Type: Change files
Origin: lodash/lodash@90e6199
Release Date: 2018-08-31
Fix Resolution: Replace or update the following files: lodash.js, test.js
Step up your Open Source Security Game with WhiteSource here
A comprehensive library for mime-type mapping
path: /JustAPotato/node_modules/unirest/node_modules/mime/package.json
Library home page: https://registry.npmjs.org/mime/-/mime-1.3.6.tgz
Dependency Hierarchy:
Affected version of mime (1.0.0 throw 1.4.0 and 2.0.0 throw 2.0.2), are vulnerable to regular expression denial of service.
Publish Date: 2017-09-27
URL: WS-2017-0330
Step up your Open Source Security Game with WhiteSource here
HTTP proxy tunneling agent. Formerly part of mikeal/request, now a standalone module.
path: /JustAPotato/node_modules/unirest/node_modules/tunnel-agent/package.json
Library home page: https://registry.npmjs.org/tunnel-agent/-/tunnel-agent-0.4.3.tgz
Dependency Hierarchy:
Versions of tunnel-agent before 0.6.0 are vulnerable to memory exposure.
This is exploitable if user supplied input is provided to the auth value and is a number.
Publish Date: 2018-04-25
URL: WS-2018-0076
Step up your Open Source Security Game with WhiteSource here
HTTP Hawk Authentication Scheme
path: /JustAPotato/node_modules/hawk/package.json
Library home page: http://registry.npmjs.org/hawk/-/hawk-3.1.3.tgz
Dependency Hierarchy:
Hawk before 3.1.3 and 4.x before 4.1.1 allow remote attackers to cause a denial of service (CPU consumption or partial outage) via a long (1) header or (2) URI that is matched against an improper regular expression.
Publish Date: 2016-04-13
URL: CVE-2016-2515
Base Score Metrics:
Type: Upgrade version
Origin: https://nodesecurity.io/advisories/77
Release Date: 2016-01-19
Fix Resolution: Update to hawk version 4.1.1 or greater.
Step up your Open Source Security Game with WhiteSource here
General purpose crypto utilities
path: /JustAPotato/node_modules/cryptiles/package.json
Library home page: http://registry.npmjs.org/cryptiles/-/cryptiles-2.0.5.tgz
Dependency Hierarchy:
Eran Hammer cryptiles version 4.1.1 earlier contains a CWE-331: Insufficient Entropy vulnerability in randomDigits() method that can result in An attacker is more likely to be able to brute force something that was supposed to be random.. This attack appear to be exploitable via Depends upon the calling application.. This vulnerability appears to have been fixed in 4.1.2.
Publish Date: 2018-07-09
URL: CVE-2018-1000620
Base Score Metrics:
Step up your Open Source Security Game with WhiteSource here
A declarative, efficient, and flexible JavaScript library for building user interfaces.
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google ❤️ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.