fix: move static function from ip to the parse-udp module #550
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What is the purpose of this pull request? (put an "X" next to item)
[ ] Documentation update
[ ] Bug fix
[ ] New feature
[X] Other, please explain:
For the past year, there has been a vulnerability in the less/not maintained
node-ip
package. While the vulnerability doesn't affectbittorrent-tracker
directly, it still results in a1 high severity vulnerability
warning after runningnpm i
on this project or any other project that hasbittorrent-tracker
as a dependency. This creates a negative impression from a customer perspective or during code audits.What changes did you make? (Give an overview)
This repository only uses a single static function from the
node-ip
package, which is unmaintained but available under the MIT license. I copied this static function directly into theparse-udp
module and removed thenode-ip
dependency entirely.I ran the tests, which show:
Additionally,
npm i
now showsfound 0 vulnerabilities
after running the command.