Re: dependency-confusion

2021-02-21 Thread Jan-Marek Glogowski
Am 21.02.21 um 23:08 schrieb Andrew Udvare: On 21/02/2021 16:43, Rene Engelhard wrote: And LibreOffice Online *does* use npm. So while LibreOffice itself shouldn't be affected, conceptually by using npm LibreOffce Online is. I think if you use 'npm install' (or 'yarn install'), the manager

Re: dependency-confusion

2021-02-21 Thread Andrew Udvare
On 21/02/2021 16:43, Rene Engelhard wrote: And LibreOffice Online *does* use npm. So while LibreOffice itself shouldn't be affected, conceptually by using npm LibreOffce Online is. I think if you use 'npm install' (or 'yarn install'), the manager should be pulling in the correct version and

Re: dependency-confusion

2021-02-21 Thread Rene Engelhard
Hi, Am 21.02.21 um 09:43 schrieb Andrew Udvare: >> On 2021-02-20, at 16:48, Jean-Baptiste Faure wrote: >> >> Hi, >> >> I certainly did not understand everything in >> https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610, but I >> wonder if

Re: dependency-confusion

2021-02-21 Thread Andrew Udvare
> On 2021-02-20, at 16:48, Jean-Baptiste Faure wrote: > > Hi, > > I certainly did not understand everything in > https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610, but I > wonder if LibreOffice could be subject to this kind of vulnerability?

dependency-confusion

2021-02-20 Thread Jean-Baptiste Faure
Hi, I certainly did not understand everything in https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610, but I wonder if LibreOffice could be subject to this kind of vulnerability? Best regards JBF -- Seuls des formats ouverts peuvent assurer la pérennité de vos documents