-
Notifications
You must be signed in to change notification settings - Fork 75
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[ FEATURE REQUEST] SFDMU depends on unsupported and outdated libraries. #869
Comments
Hello, @PawelWozniak Thank you for reporting a bug. Cheers |
I would add to this that both alasql and madge are very outdates and contain multiple "high" level vulnerabilities. alasql latest is 4.5.1, sfdmu is on 0.6.4 |
Hello, All these vulnerabilities do not matter since the tool is used only locally. I do not plan to update dependencies in the near future, as it might require refactoring and regression tests due to breaking changes in the newest versions. If you have any doubts regarding security, please stop using sfdmu. |
In my opinion since this tool is developed under Salesforce Developers official account and Salesforce repeatedly says that Trust is number one for them then security should be considered as important. |
Ok. This is your opinion and understanding of "trust" in context of this tool as well as a reported issues. Your use of the product is under the code of conduct and terms of use. Please take in account that this is not Salesforce product and sf can't take full responsibility on it. From my side, I give the best what I can to maintain this tool. The rest is on the end-user which sees what he uses and this is the value of sf "trust" in terms of "transparency". |
I understand that fixing such dependency is complex as it can cause some side effects. I am glad that you improve this tool it is beneficial for everyone. |
Converted to "feature request" and put to my roadmap. I am closing this issue for now. I will review the feature request at a later time, but please note that there is no guarantee that this update will be implemented. I will provide further updates if there are any developments. Best regards. |
These dependencies has been updated to the latest version. |
Hello @PawelWozniak, Thanks again for pointing out the outdated libraries used in the project. My priority is to avoid any breaking changes or regressions, as SFDMU is actively used by a large number of organizations and businesses. Therefore, I prefer not to proceed with the upgrade at this time, as SFDMU continues to function well despite some minor warnings that may appear. For now, I’ve postponed this upgrade, but it might be revisited later when it becomes more feasible. |
@hknokh2 Thank you for the update. This tool works well so keep it going. Thank you. |
Describe the bug
Just installed plugin and got many warnings during this process, here is an output:
To Reproduce
Unsinstall whole SF CLI so it remove also plugins.
Install SF CLI.
Install sfdx-git-delta with command
sf plugins install sfdx-git-delta
Expected behavior
Plugin install without warning.
export.json
Not applicable to this issue.
Log file
Not applicable to this issue.
_target.csv file.
Not applicable to this issue.
The text was updated successfully, but these errors were encountered: