Page MenuHomePhabricator

marvin: critical severity security vulnerability detected in macaddress < 0.2.9 defined in package-lock.json.
Closed, DeclinedPublic

Description

From Github:

Known critical severity security vulnerability detected in macaddress < 0.2.9 defined in package-lock.json.
package-lock.json update suggested: macaddress ~> 0.2.9.

Related Objects

Event Timeline

I don't think marvin is being actively developed / maintained, and would recommend archiving it.

@Sniedzielski -> @Niedzielski

It seems Stephen and Joaquin did the last patches on marvin.git, the last ones being from ~ January 2018. Is Marvin still a thing or should we look at archiving the git repository / phabricator project etc?

Yes, the project is stalled for the foreseeable future and should be archived. I've updated the project description in Phabricator.

Yes, the project is stalled for the foreseeable future and should be archived. I've updated the project description in Phabricator.

Will someone update https://www.mediawiki.org/wiki/Reading/Web/Projects/NewMobileWebsite ? Like {{Historical}} or such?

Legoktm mentioned this in T205170: Archive marvin.

Filed T205170 for the archival effort, I'll decline this.

Legoktm changed the visibility from "Custom Policy" to "Public (No Login Required)".Sep 22 2018, 12:11 AM