瀏覽代碼

- Removed binary version of bcrypt because of vulnerability that has issue that is not fixed yet. This may cause some slowdown.

Thanks to xet7 !
Lauri Ojansivu 7 年之前
父節點
當前提交
5ded2e5121
共有 1 個文件被更改,包括 4 次插入2 次删除
  1. 4 2
      CHANGELOG.md

+ 4 - 2
CHANGELOG.md

@@ -1,8 +1,10 @@
 # Upcoming Wekan release
 
 * [Remove binary version of bcrypt](https://github.com/wekan/wekan/commit/4b2010213907c61b0e0482ab55abb06f6a668eac)
-  because of [vulnerability that is not fixed yet](https://github.com/kelektiv/node.bcrypt.js/issues/604) that
-  [is not fixed yet](https://github.com/kelektiv/node.bcrypt.js/pull/606).
+  because of [vulnerability](https://nodesecurity.io/advisories/612) that has [issue that is not fixed
+  yet](https://github.com/kelektiv/node.bcrypt.js/issues/604) and
+  and [not yet merged pull request](https://github.com/kelektiv/node.bcrypt.js/pull/606).
+  This may cause some slowdown.
 
 Thanks to GitHub user xet7 for contributions.