Openbravo Issue Tracking System - Retail Modules | ||||||||||||
View Issue Details | ||||||||||||
ID | Project | Category | View Status | Date Submitted | Last Update | |||||||
0049377 | Retail Modules | Nexo Implementation | public | 2022-05-23 15:22 | 2022-06-27 17:15 | |||||||
Reporter | shuehner | |||||||||||
Assigned To | adrianromero | |||||||||||
Priority | normal | Severity | major | Reproducibility | have not tried | |||||||
Status | closed | Resolution | fixed | |||||||||
Platform | OS | 5 | OS Version | |||||||||
Product Version | ||||||||||||
Target Version | Fixed in Version | |||||||||||
Merge Request Status | ||||||||||||
Review Assigned To | ||||||||||||
OBNetwork customer | ||||||||||||
Support ticket | ||||||||||||
Regression level | ||||||||||||
Regression date | ||||||||||||
Regression introduced in release | ||||||||||||
Regression introduced by commit | ||||||||||||
Triggers an Emergency Pack | No | |||||||||||
Summary | 0049377: nexoprovider module pacakge.json semver should be reviewed and package-lock.json should be updated | |||||||||||
Description | a.) package.json of nexoprovider module hardcodes versions of its dependencies very strictly. That should be reviewed and unless special reason exists more typical ^ semver instead of = should be used. JSONIX part is managed in the related design defect https://issues.openbravo.com/view.php?id=49609 [^] b.1) npm audit issues (easy) run "npm audit fix" b.2) npm audit issues xmldom avoiding old versions is still not possible as depended upon by jsonix@3.0.0 c.) jsonix@3.0.0 contains jsonix-schema-compiler-full.jar including outdated other libraries jsonix-schema-compiler-full.jar (shaded: commons-beanutils:commons-beanutils:1.9.2) jsonix-schema-compiler-full.jar (shaded: commons-collections:commons-collections:3.2.1) Note: - jsonix upstream seems to not have released a new version >3.0.0 yet | |||||||||||
Steps To Reproduce | run npm audit run owasp-dependency check with "npm install" done before in the module | |||||||||||
Proposed Solution | ||||||||||||
Additional Information | ||||||||||||
Tags | No tags attached. | |||||||||||
Relationships |
| |||||||||||
Attached Files | ||||||||||||
Issue History | ||||||||||||
Date Modified | Username | Field | Change | |||||||||
2022-05-23 15:22 | shuehner | New Issue | ||||||||||
2022-05-23 15:22 | shuehner | Assigned To | => Triage Platform Conn | |||||||||
2022-05-23 15:22 | shuehner | Triggers an Emergency Pack | => No | |||||||||
2022-06-01 10:50 | adrianromero | Assigned To | Triage Platform Conn => adrianromero | |||||||||
2022-06-20 16:29 | hgbot | Note Added: 0138571 | ||||||||||
2022-06-20 17:49 | adrianromero | Issue cloned | 0049609 | |||||||||
2022-06-20 17:49 | adrianromero | Relationship added | related to 0049609 | |||||||||
2022-06-20 17:51 | adrianromero | Description Updated | bug_revision_view_page.php?rev_id=24323#r24323 | |||||||||
2022-06-27 17:15 | hgbot | Resolution | open => fixed | |||||||||
2022-06-27 17:15 | hgbot | Status | new => closed | |||||||||
2022-06-27 17:15 | hgbot | Note Added: 0138795 | ||||||||||
2022-06-27 17:15 | hgbot | Note Added: 0138796 | ||||||||||
2022-06-27 17:15 | hgbot | Note Added: 0138797 |
Notes | |||||
|
|||||
|
|
||||
|
|||||
|
|
||||
|
|||||
|
|
||||
|
|||||
|
|