Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

massive spike in dependencies, including security vulnerabilities #315

Closed
electrovir opened this issue May 31, 2023 · 5 comments
Closed

Comments

@electrovir
Copy link

Some went seriously wrong with the version 0.4.4 release: it has 401 direct dependencies, including security vulnerabilities, while version 0.4.3 has 0 dependencies.

@LeaVerou
Copy link
Member

Yikes, thanks for letting us know! My first thought was that something that was a dev dependency must have been added as a regular dependency, but it doesn't look like it. Investigating…

@LeaVerou
Copy link
Member

Ok, that's odd. The package.json that's published on npm seems to have a huge list of dependencies, but the package.json in the repo does not. WTAF.

@LeaVerou
Copy link
Member

Fixed in v0.4.4-patch.1! Thanks again so much for bringing this to our attention! Still no clue how this happened. 🤷🏽‍♀️

@jgerigmeyer
Copy link
Member

@LeaVerou Unfortunately while v0.4.4-patch.1 is installed correctly as the latest release, it doesn't satisfy common semver ranges -- for example, existing projects with "colorjs.io": "^0.4.3" will now get v0.4.4 installed instead of the patched release. Would you consider re-releasing as v0.4.5?

@LeaVerou
Copy link
Member

LeaVerou commented Jun 5, 2023

Yikes. that seems like a bug in semver, but fixed anyway. @jgerigmeyer do you use the same username on npm? I should add you there too

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants