mirror of
https://github.com/fatedier/frp.git
synced 2026-05-15 08:05:49 -06:00
[GH-ISSUE #4741] Vulnerabilities in the latest version #3747
Labels
No labels
In Progress
WIP
WaitingForInfo
bug
doc
duplicate
easy
enhancement
future
help wanted
invalid
lifecycle/stale
need-issue-template
need-usage-help
no plan
proposal
pull-request
question
todo
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: github-starred/frp#3747
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @aleksandr-orca on GitHub (Apr 1, 2025).
Original GitHub issue: https://github.com/fatedier/frp/issues/4741
Bug Description
Hello, first of all thank you so much for this project, it's really convenient to use and impressively effective. What I'm concerned about is the frequency of the latest updates. I imagine how hard sometimes to maintain the open source project, but from security perspective new vulnerabilities are getting discovered each day, and without frequent dependency updates there's a high risk of being affected by this.
Currently, there are 3 vulnerabilities we found caused by dependencies used in this project, sorted by criticality:
Is it possible to resolve those? maybe some automation could be set up to update dependencies with security issues? For example, Trivy provides a free-to-use project in order to detect these vulns, so in combination of this and some automation most of the security issues could be resolved, because most of the time these are happening because of the outdated dependency versions
frpc Version
v0.61.2
frps Version
v0.61.2
System Architecture
any linux, I believe any arch in general
Configurations
doesn't matter
Logs
No response
Steps to reproduce
No response
Affected area
@github-actions[bot] commented on GitHub (Apr 16, 2025):
Issues go stale after 14d of inactivity. Stale issues rot after an additional 3d of inactivity and eventually close.