2023-08-08 Cacti Maintainers Agenda
Hyperledger is committed to creating a safe and welcoming community for all. For more information please visit the Hyperledger Code of Conduct.
Hyperledger is committed to creating a safe and welcoming community for all. For more information please visit our Code of Conduct: Hyperledger Code of Conduct
Discussion
- gRPC legacy versions
- Critical and high security vulnerabilities
- ejs
- https://github.com/hyperledger/cacti/security/dependabot/643
- $ yarn why ejs -R
├─ @hyperledger/cacti-weaver-besu-cli@workspace:weaver/samples/besu/besu-cli
│ └─ gluegun@npm:5.1.2 (via latest)
│ └─ ejs@npm:3.1.6 (via npm:3.1.6)
│
└─ @hyperledger/cacti-weaver-fabric-cli@workspace:weaver/samples/fabric/fabric-cli
└─ gluegun@npm:5.1.2 (via latest)
- mongoose
- https://github.com/hyperledger/cacti/security/dependabot/700
- Detected in mongoose (npm) • examples/test-run-transaction/supply-chain-app-stub/package.json
- ejs
- 2.0.0-alpha.2 release issuance
- Ad-hoc Discussion Items
Recording
TBD