• The developer of the ‘node-ip’ project made the GitHub repository read-only after disputing the severity of a reported vulnerability (CVE-2023-42282).
  • The vulnerability involved incorrect identification of private IP addresses in non-standard formats, but the developer argued it had a dubious security impact.
  • The situation highlights ongoing issues with unverified CVE reports causing unnecessary panic and frustration for open-source project maintainers.
  • lemmyvore@feddit.nl
    link
    fedilink
    English
    arrow-up
    13
    arrow-down
    3
    ·
    4 months ago

    Clearly it wasn’t maintained.

    Lol. It’s an IP library. IP classifications haven’t changed. What could he possibly update?

    • spartanatreyu@programming.dev
      link
      fedilink
      arrow-up
      2
      ·
      4 months ago

      There’s a whole bunch of pull requests and issues sitting there for a start.

      Personally I’d also update the example in the readme and set an engine value in the package.json file.