Skip to content

[BUG] Fix cve on new patch #1844

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
5 tasks done
orlovds opened this issue Apr 29, 2025 · 4 comments
Open
5 tasks done

[BUG] Fix cve on new patch #1844

orlovds opened this issue Apr 29, 2025 · 4 comments
Assignees
Labels
👤 Awaiting Maintainer Response [ISSUE] Response from repo author is pending 🐛 Bug [ISSUE] Ticket describing something that isn't working

Comments

@orlovds
Copy link

orlovds commented Apr 29, 2025

Environment

Self-Hosted (Docker)

System

No response

Version

3.1.1

Describe the problem

Good day
Is it possible to fix vulnerabilities in the new patch (attached report)?

Thank you in advance

Vulnerability_Report_Dashy.pdf

Additional info

Good day
Is it possible to fix vulnerabilities in the new patch (attached report)?

Thank you in advance

Please tick the boxes

@orlovds orlovds added the 🐛 Bug [ISSUE] Ticket describing something that isn't working label Apr 29, 2025
@github-project-automation github-project-automation bot moved this to Awaiting Triage in Dashy V3 Apr 29, 2025
@CrazyWolf13
Copy link
Collaborator

Hi
Appreciate the time for the report!

I think you'll be best off sending an email to @Lissy93 [email protected]

Lately it has been a bit quiet around her and especially dashy.

PS: Therefore I wouldn't expect a quick fix.

@Lissy93
Copy link
Owner

Lissy93 commented May 6, 2025

Hi there @orlovds and @CrazyWolf13, thanks for raising this and including the Trivy scan output. I appreciate your attention to security.

Appologies for not being more present here recently. I'll work more on Dashy again over the next few weeks, and slowly catchup on issues.


Most of the issues flagged here are related to dependencies of dependencies or the base Alpine/Node image — not Dashy’s own code. This is common across most modern Dockerized Node apps. And none of the flagged vulnerabilities are known to be directly exploitable in Dashy’s current usage.

In short, these automated reports are a helpful reference but don’t necessarily imply exploitable vulnerabilities in context. Still, I’ll go through and address what’s actionable.

@CrazyWolf13
Copy link
Collaborator

Hi @Lissy93

Did not expect that reply, thanks for chiming back in :)

Yeah that's what I expected but thought I would let you judge on this.

Feel free to reply to me on matrix, if you want to pick up dashy again.

@orlovds
Copy link
Author

orlovds commented May 6, 2025

@Lissy93 many thanks

@liss-bot liss-bot added the 👤 Awaiting Maintainer Response [ISSUE] Response from repo author is pending label May 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
👤 Awaiting Maintainer Response [ISSUE] Response from repo author is pending 🐛 Bug [ISSUE] Ticket describing something that isn't working
Projects
Status: Awaiting Triage
Development

No branches or pull requests

4 participants