hassio-addons/addon-node-red

node-red missing critical updates / can not remove unused palettes #657

gj52 posted onGitHub

Problem/Motivation

LOG: found 14 vulnerabilities (2 low, 8 moderate, 4 high)

Expected behavior

no high (and moderate) vulnerabilities -> deletion of paletted blocked??

Actual behavior

Node-Red Log:

Add-on: Node-RED Flow-based programming for the Internet of Things


Add-on version: 7.0.0 You are running the latest version of this add-on. System: HassOS 4.12 (armv7 / raspberrypi3) Home Assistant Core: 0.114.2 Home Assistant Supervisor: 234


Please, share the above information when looking for help or support in, e.g., GitHub, forums or the Discord chat.


[cont-init.d] 00-banner.sh: exited 0. [cont-init.d] 01-log-level.sh: executing... [cont-init.d] 01-log-level.sh: exited 0. [cont-init.d] nginx.sh: executing... [cont-init.d] nginx.sh: exited 0. [cont-init.d] node-red.sh: executing... patching file nodes/ui_base.html Hunk #1 succeeded at 1177 (offset 646 lines). audited 295 packages in 16.333s 14 packages are looking for funding run npm fund for details found 14 vulnerabilities (2 low, 8 moderate, 4 high) run npm audit fix to fix them, or npm audit for details [cont-init.d] node-red.sh: exited 0

Steps to reproduce

installed palettes: node-red 1.1.0 node-red-contrib-actionflows 2.0.3 node-red-contrib-alexa-home-skill 0.1.17 node-red-contrib-avr-yamaha 0.8.6 node-red-contrib-bigtimer 2.3.1 node-red-contrib-cast 0.2.15 node-red-contrib-config 1.1.3 node-red-contrib-counter 0.1.5 node-red-contrib-cron 0.0.4 node-red-contrib-fritz 1.3.9 node-red-contrib-home-assistant-websocket 0.24.1 node-red-contrib-http-request 0.1.14 node-red-contrib-influxdb 0.4.1 node-red-contrib-interval-length 0.0.4 node-red-contrib-looptimer 0.0.8 node-red-contrib-modbus 5.13.3 node-red-contrib-moment 3.0.3 node-red-contrib-pjlink 1.0.4 node-red-contrib-startup-trigger 0.1.0 node-red-contrib-state-machine 1.2.0 node-red-contrib-statistics 2.2.2 node-red-contrib-stoptimer 0.0.7 node-red-contrib-sun-position 1.1.3 node-red-contrib-sunevents 2.0.3 node-red-contrib-telegrambot 8.4.0 node-red-contrib-time-range-switch 1.0.0 node-red-contrib-timecheck 1.1.0 node-red-contrib-traffic 0.2.1 node-red-contrib-wait-paths 0.3.2 node-red-dashboard 2.23.2 node-red-node-base64 0.2.1 node-red-node-email 1.7.8 node-red-node-feedparser 0.1.16 node-red-node-geofence 0.1.2 node-red-node-msgpack 1.2.1 node-red-node-pi-gpio 1.1.1 node-red-node-ping 0.2.1 node-red-node-random 0.2.0 node-red-node-rbe 0.2.9 node-red-node-sentiment 0.1.6 node-red-node-serialport 0.10.3 node-red-node-smooth 0.1.2 node-red-node-suncalc 1.0.1 node-red-node-tail 0.1.1 node-red-node-twitter 1.1.6

Proposed changes


This happens. All are updated to the latest version available.

posted by frenck over 4 years ago

Fund this Issue

$0.00
Funded

Pull requests