question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

docs: mailgun-js is deprecated and has security vulnerabilities. Please update your guides.

See original GitHub issue

I’m posting this here because it’s relevant, although the issue is not with this library.

Your official Mailgun documentation for NodeJS implementation (https://documentation.mailgun.com/en/latest/user_manual.html?highlight=batch sending#sending-via-api) refers to a deprecated dependency mailgun-js.

The deprecated package mailgun-js has a High security vulnerability in one of it’s sub-dependencies which cannot be auto fixable.

Screen Shot 2021-03-31 at 12 48 15

Please update your guides to use examples with this library.

Issue Analytics

  • State:closed
  • Created 2 years ago
  • Reactions:20
  • Comments:9 (3 by maintainers)

github_iconTop GitHub Comments

2reactions
olexandr-mazepacommented, Jul 6, 2021

@MrSwitch Good catch. Thank you. There were a bunch of open issues that pointed to vulnerability in the deprecated mailgun-js library. Accidentally I decided that this is one of them.

1reaction
zacharytyhaczcommented, Apr 29, 2021

Yes, we should be using the official mailgun.js package instead: https://github.com/mailgun/mailgun-js/issues/122

Read more comments on GitHub >

github_iconTop Results From Across the Web

docs: mailgun-js is deprecated and has security vulnerabilities ...
The deprecated package mailgun-js has a High security vulnerability in one of it's sub-dependencies which cannot be auto fixable.
Read more >
mailgun-js - npm Package Health Analysis - Snyk
Learn more about mailgun-js: package health score, popularity, security, ... Snyk scans all the packages in your projects for vulnerabilities and provides ...
Read more >
TLS Version 1.0 and 1.1 Deprecation - Mailgun
Why deprecate TLS 1.0 and 1.1? The older TLS versions are riddled with security vulnerabilities. As such, these protocols are updated over time ......
Read more >
Cannot Install Ghost on Plesk Obsidian with Nods.js
I want to install Ghost CMS for a domain hosted on my plesk server. ... for details. npm WARN deprecated node-pre-gyp@0.11.0: Please upgrade...
Read more >
Open-source Attributions
New Relic will have no liability to you for direct, indirect, consequential ... a copy of this software and associated documentation files (the...
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found