[meterian] Fixed vulnerable dependencies #2
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Dear development team @QuBiT,
My name is Bruno and as part of ongoing projects at meterian.io, we regularly scan open source projects on GitHub, BitBucket and other repositories in order to warn developers about vulnerabilities in their included libraries, which may negatively affect their products.
Analysing your project we detected it may be exposed to these publicly disclosed vulnerabilities:
You can read our assessment report here, it includes also some suggestion regarding obsolete libraries that appear still to be used in your project.
We kindly recommend you accept this PR as a starting point in order to resolve this problem, although this is still an incomplete solution, as in order to fully resolve the issue you will need also a major upgrade of at least one library. Please note (and excuse my shameless plug!) we distribute a client solution that can be easily integrated into your build pipeline to protect both open and closed source projects. We are able to find vulnerabilities, suggest library upgrades and (soon) detect license violations.
Please do not hesitate to contact us: we are currently running a pilot and we will be glad to have you on board!
[email protected]