Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Project status and security #686

Open
binarious opened this issue Sep 19, 2024 · 0 comments
Open

Project status and security #686

binarious opened this issue Sep 19, 2024 · 0 comments

Comments

@binarious
Copy link

I've noticed some closed issues regarding the project's status, with responses stating that the project isn't abandoned, despite the fact that the latest release was over two years ago.

In the latest release, 10 of the composer dependencies have open vulnerabilities (8 of which are present even on the master branch). Additionally, the Docker image for the latest release is still based on PHP 7.4, which reached end-of-life at the end of 2023. Trivy also reports 150 open CVEs for this image, which raises concerns—especially for anyone using it in a production environment.

I also noticed that the Dockerfile disables StrictHostKeyChecking, which is generally considered a poor security practice. Could you provide some insight into the rationale behind this decision?

Additionally, it would be helpful to get some clarity on the current status of the project and any plans for future updates.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant