Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: dep rolled package-lock #1402

Merged
merged 1 commit into from
Feb 26, 2025
Merged

chore: dep rolled package-lock #1402

merged 1 commit into from
Feb 26, 2025

Conversation

breautek
Copy link
Contributor

Platforms affected

N/A

Motivation and Context

Resolves:

cross-spawn  7.0.0 - 7.0.4
Severity: high
Regular Expression Denial of Service (ReDoS) in cross-spawn - https://github.com/advisories/GHSA-3xgq-45jj-v275
fix available via `npm audit fix`
node_modules/cross-spawn

Description

Ran npm upgrade to roll sub-dependencies

Testing

Ran npm test

Checklist

  • I've run the tests to see all new and existing tests pass
  • I added automated test coverage as appropriate for this change
  • Commit is prefixed with (platform) if this change only applies to one platform (e.g. (android))
  • If this Pull Request resolves an issue, I linked to the issue in the text above (and used the correct keyword to close issues using keywords)
  • I've updated the documentation if necessary

@dpogue
Copy link
Member

dpogue commented Feb 26, 2025

Seems like there are conflicts

@breautek
Copy link
Contributor Author

Ah i probably forgot to rebase my fork

@breautek
Copy link
Contributor Author

rebased, and confirmed that cross-spawn vulnerability was still existing in apache's master, so the PR description is still relevant 👍

@dpogue dpogue merged commit 5d1f5bc into apache:master Feb 26, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants