Skip to content

NPM Audit - 17 high vulnerabilities for solid-server 5.8.5 #1821

Description

@msbachler

Hi,

I was wondering if you would be able to address the high vulnerabilities currently in the solid-server packages used?
If you run NPM Audit it says there are 17 high vulnerabilities and my university gets quite strict about me running code with high vulnerabilities.
I would be most grateful if you could take at look and perhaps at least reduce the list, if not eliminate it?

Kind regards.

Activity

  1. msbachler commented on Aug 28, 2025

    @msbachler
    Author

    It is now 2 Critical and 10 high. Any chance of updating the packages?

  2. bourgeoa commented on Aug 28, 2025

    @bourgeoa
    Member

    Lots of works is going on in Solid managed dependencencies SolidOS and Rdflib.
    I hope it will soon solve your University concerns.

    Help is also deeply needed.

    Cc @timea-solid

  3. bourgeoa commented on Nov 7, 2025

    @bourgeoa
    Member

    @msbachler

    The new npm version solid-server@5.8.8 as no critical nor high vulnerabilities.

    There only one remaining vulnerability

    # npm audit report
    
    bootstrap  3.1.1 - 3.4.1
    Severity: moderate
    Bootstrap Vulnerable to Cross-Site Scripting in its Popover and Tooltip Components - https://github.com/advisories/GHSA-q58r-hwc8-rm9j
    Bootstrap Cross-Site Scripting (XSS) vulnerability for data-* attributes - https://github.com/advisories/GHSA-vxmc-5x29-h64v
    fix available via `npm audit fix --force`
    Will install bootstrap@5.3.8, which is a breaking change
    node_modules/bootstrap
    
    

    the reason this one is not resolve is due to Boostrap licence.
    Bootstrap is not directly used but only bootstrap CSS

  4. msbachler commented on Nov 10, 2025

    @msbachler
    Author

    That is great news. Thank you so much. I will update now!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions