Skip to content

SQLite3 package has some vulnerabilities. #3466

Description

@yakanechi

What happened:
The package version of SQLite3 v5.1.7 contains vulnerabilities.

  • sqlite3@5.1.7 > node-gyp@8.4.1 > glob@7.2.3 > minimatch@3.1.2
  • sqlite3@5.1.7 > tar@6.2.1

However, updates to SQLite3 have been suspended for over two years.

What you expected to happen:

Dependency packages containing vulnerabilities are not used.
Alternatively, stop using SQLite3.

How to reproduce it:

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions