Skip to content

Package Vulnerability: Dependency Confusion Attack - uWebSockets.js #596

Answered by enisdenjo
SwhiteMHC asked this question in Q&A
Discussion options

You must be logged in to vote

I know about that old article and the uWS author explains there why NPM is not for him. I respect his choice.

Furthermore, uWS is an optional peer dependency and as such does not pose a security threat from within the package.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by enisdenjo
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
question Further information about the library is requested
2 participants
Converted from issue

This discussion was converted from issue #595 on November 19, 2024 11:57.