Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Tracking issue: remove http-parser #317263

Open
3 of 10 tasks
eclairevoyant opened this issue Jun 4, 2024 · 2 comments
Open
3 of 10 tasks

Tracking issue: remove http-parser #317263

eclairevoyant opened this issue Jun 4, 2024 · 2 comments
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one 5. scope: tracking Long-lived issue tracking long-term fixes or multiple sub-problems

Comments

@eclairevoyant
Copy link
Contributor

eclairevoyant commented Jun 4, 2024

http-parser is an abandoned project as of November 2022 and considering it's meant to parse arbitrary input over HTTP, keeping the package around likely constitutes a security risk. Though there aren't open publicised CVEs that I could find for http-parser itself, the followup project llhttp does in fact have several CVEs, which ups the risk for an abandoned project IMO.

Current dependents are:

@eclairevoyant eclairevoyant added 1.severity: security Issues which raise a security issue, or PRs that fix one 5. scope: tracking Long-lived issue tracking long-term fixes or multiple sub-problems labels Jun 4, 2024
@pyrox0
Copy link
Member

pyrox0 commented Jun 4, 2024

@pyrox0 pyrox0 mentioned this issue Jun 15, 2024
13 tasks
@eclairevoyant eclairevoyant closed this as not planned Won't fix, can't repro, duplicate, stale Sep 10, 2024
@linsui linsui reopened this Nov 17, 2024
@linsui
Copy link
Contributor

linsui commented Nov 17, 2024

http-parser has been removed from jami.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one 5. scope: tracking Long-lived issue tracking long-term fixes or multiple sub-problems
Projects
None yet
Development

No branches or pull requests

3 participants