From 5ded2e512141a148a0d33fc3059564af74e95b62 Mon Sep 17 00:00:00 2001 From: Lauri Ojansivu Date: Sat, 26 May 2018 07:44:36 +0300 Subject: - Removed binary version of bcrypt because of vulnerability that has issue that is not fixed yet. This may cause some slowdown. Thanks to xet7 ! --- CHANGELOG.md | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) (limited to 'CHANGELOG.md') diff --git a/CHANGELOG.md b/CHANGELOG.md index a9955ac0..a34fea44 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,8 +1,10 @@ # Upcoming Wekan release * [Remove binary version of bcrypt](https://github.com/wekan/wekan/commit/4b2010213907c61b0e0482ab55abb06f6a668eac) - because of [vulnerability that is not fixed yet](https://github.com/kelektiv/node.bcrypt.js/issues/604) that - [is not fixed yet](https://github.com/kelektiv/node.bcrypt.js/pull/606). + because of [vulnerability](https://nodesecurity.io/advisories/612) that has [issue that is not fixed + yet](https://github.com/kelektiv/node.bcrypt.js/issues/604) and + and [not yet merged pull request](https://github.com/kelektiv/node.bcrypt.js/pull/606). + This may cause some slowdown. Thanks to GitHub user xet7 for contributions. -- cgit v1.2.3-1-g7c22