Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Please upgrade libraries #307

Open
luiscarlosjayk opened this issue Aug 29, 2022 · 4 comments
Open

Please upgrade libraries #307

luiscarlosjayk opened this issue Aug 29, 2022 · 4 comments
Assignees

Comments

@luiscarlosjayk
Copy link

Hi, while installing I'm getting this warnings:

warning docusign-esign > [email protected]: Please upgrade to v7.0.2+ of superagent.  We have fixed numerous issues with streams, form-data, attach(), filesystem errors not bubbling up (ENOENT on attach()), and all tests are now passing.  See the releases tab for more information at <https://github.com/visionmedia/superagent/releases>.
warning docusign-esign > superagent > [email protected]: Please upgrade to latest, formidable@v2 or formidable@v3! Check these notes: https://bit.ly/2ZEqIau
[3/5] Fetching packages...
@sylvainleb376
Copy link

Those are not errors but warnings that won't affect your working and installation.
Could you please indicate precisely how did you fell on this message in order I could report your finding to the Engineering team?

@UpendraNallapareddy
Copy link

@sylvainleb376

When installing first time by this install command
npm add docusign-esign

We get the warning about deprecated libraries. This may break anytime when infrastructure is upgraded.

npm WARN deprecated [email protected]: Please upgrade to latest, formidable@v2 or formidable@v3! 
npm WARN deprecated [email protected]: Please upgrade to v7.0.2+ of superagent.

Thanks

@Loigor
Copy link

Loigor commented Jun 1, 2023

@sylvainleb376

Is it possible to update superagent package?
Superagent 3.8.2 has 'high' vulnerability GHSA-hrpp-h998-j3pp

@NicolasEspiau-stilll
Copy link

I second the demand.

Docusign is supposed to be a reliable and secure tool, it cannot be if its SDKs are based on dependencies that have important
and high vulnerabilities.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants