Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Urgent Need to Upgrade node-notifier package to 8.0.1 #254

Closed
palisadoes opened this issue May 22, 2021 · 2 comments
Closed

Urgent Need to Upgrade node-notifier package to 8.0.1 #254

palisadoes opened this issue May 22, 2021 · 2 comments
Assignees
Labels
bug Something isn't working good first issue Good for newcomers

Comments

@palisadoes
Copy link
Contributor

Describe the bug
A clear and concise description of what the bug is.

  1. We must remove exposure to the CVE-2020-7789OS Command Injection in node-notifier vulnerability.
  2. This will need to be done manually as there are cross-dependencies that must be resolved.

To Reproduce
Steps to reproduce the behavior:

  1. See screen shots

Expected behavior
Upgrade node-notifier package to 8.0.1

Actual behavior
Using vulnerable version

Screenshots
If applicable, add screenshots to help explain your problem.
image

Additional details
None

@palisadoes palisadoes added bug Something isn't working good first issue Good for newcomers labels May 22, 2021
@github-actions github-actions bot added dependencies unapproved Unapproved for Pull Request labels May 22, 2021
@impiyush83
Copy link
Contributor

@palisadoes Please assign this to me

@palisadoes palisadoes removed the unapproved Unapproved for Pull Request label May 26, 2021
palisadoes added a commit that referenced this issue May 26, 2021
@impiyush83
Copy link
Contributor

@palisadoes We can close this.

palisadoes added a commit that referenced this issue Jun 1, 2021
* Bump y18n from 4.0.0 to 4.0.1

Bumps [y18n](https://github.com/yargs/y18n) from 4.0.0 to 4.0.1.
- [Release notes](https://github.com/yargs/y18n/releases)
- [Changelog](https://github.com/yargs/y18n/blob/master/CHANGELOG.md)
- [Commits](https://github.com/yargs/y18n/commits)

Signed-off-by: dependabot[bot] <support@github.com>

* Update README.md

* Update README.md

* Update README.md

* Update README.md

* Update README.md

* Update README.md

* Update README.md

* Update README.md

* fix: Create INSTALLATION.md File (#220)

* Updated INSTALLATION.md

Node js is not needed for Docker installation

* Deleted docs folder

* Fixes #222

* Add files via upload

* Update CONTRIBUTING.md

* Update CONTRIBUTING.md

* Update PR-guidelines.md

* Update CONTRIBUTING.md

* Update issue.yml

* Bump hosted-git-info from 2.8.8 to 2.8.9

Bumps [hosted-git-info](https://github.com/npm/hosted-git-info) from 2.8.8 to 2.8.9.
- [Release notes](https://github.com/npm/hosted-git-info/releases)
- [Changelog](https://github.com/npm/hosted-git-info/blob/v2.8.9/CHANGELOG.md)
- [Commits](npm/hosted-git-info@v2.8.8...v2.8.9)

Signed-off-by: dependabot[bot] <support@github.com>

* Create linter.yml

* Update linter.yml

* Update linter.yml

* Update linter.yml

* Create test.js

* Update test.js

* Update test.js

* Update test.js

* Update test.js

* Update test.js

* Update linter.yml

* Update linter.yml

* Delete test.js

* Update linter.yml

* Update linter.yml

* Update linter.yml

* Update linter.yml

* Update linter.yml

* Update linter.yml

* Update linter.yml

* Update linter.yml

* Update linter.yml

* Update linter.yml

* Create lint.yml

* Update linter.yml

* Delete lint.yml

* Update linter.yml

* bug issue#223 resolved

* bug fix issue #223

* Delete chats.spec.js

* Delete chats.spec.dev.js

* Create chats.spec.js

* Updated branching strategy in CONTRIBUTING.md

* bug: #253 netmask bump

* bug: #253 netmask bump

* Pagination for members of organization

* feat: #263 Added i18n,  error interface library

* bugFix: #254 Bumped up node-notifier

* feat: #263 fixed error objects

* feat: #263 fixed naming conventions

* feat: #263 fixed linting

* feat: #263 fixed errors

* feat: #263 format graphql error object

* feat: #263 Fixed plural validation error handling

* feat: #263 Added util function

* feat: #263 Added hindi translations

* feat: #263 Added hindi translations

* feat: #263 Added comments for error classes

* feat: #263 Added ['hi', 'en', 'zh', 'fr', 'sp'] supported languages

* feat: #263 Packaged errors and talawa-request-context as library

* feat: #263 Packaged errors and talawa-request-context as library

* feat: #263 Fixed eslint  errors

* Update pull_request_template.md

* Feature/logging (#267)

* feat: #264 logger

* feat: #264 removed  nanoid

* feat: #264 added custom libs

* feat: #264 added custom libs

* feat: #264 removed request tracing

* feat: #264 Used custom  lib logger

* feat: #264 Compatible request tracing via logger

* feat: #264 Logging  error message

* Update Installation.md (#270)

Clarify more with the required steps for installation.

* Pagination added for posts by organisation (#273)

* pagination added for posts by org

* es lint fix

* Model and Schema update for appLanguage (#281)

* model and schema update

* language update mutation added

* language code added

* lng

* bugFix: #288 ws package upgrade (#293)

* bug fix : events can be removed by event admins or org admins only (#271)

* bug fix : events can be removed by event admins or org admins only

* replaced .filter method with .includes

* replaced errors with error objects for translation

* Schema Update to avoid master failure (#299)

* changes for workflow update

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Peter Harrison <blackriver@simiya.com>
Co-authored-by: Saumya Pandey <sp160899@gmail.com>
Co-authored-by: Hrishikesh-Bhagwat <79875904+Hrishikesh-Bhagwat@users.noreply.github.com>
Co-authored-by: ShubhamBhardwaj <shubham.11901502@lpu.in>
Co-authored-by: mihdas <46824909+mihdas@users.noreply.github.com>
Co-authored-by: ssaumyaa7 <saumya4799@gmail.com>
Co-authored-by: DangaRanga <jasonblue1626@gmail.com>
Co-authored-by: Jason Gayle <55003601+DangaRanga@users.noreply.github.com>
Co-authored-by: impiyush83 <nalawadepiyush@gmail.com>
Co-authored-by: Uttam kumar <72701081+helper-uttam@users.noreply.github.com>
Co-authored-by: Akshat Garg <60404253+akshatgarg12@users.noreply.github.com>
palisadoes added a commit that referenced this issue Jun 1, 2021
* Bump y18n from 4.0.0 to 4.0.1

Bumps [y18n](https://github.com/yargs/y18n) from 4.0.0 to 4.0.1.
- [Release notes](https://github.com/yargs/y18n/releases)
- [Changelog](https://github.com/yargs/y18n/blob/master/CHANGELOG.md)
- [Commits](https://github.com/yargs/y18n/commits)

Signed-off-by: dependabot[bot] <support@github.com>

* Update README.md

* Update README.md

* Update README.md

* Update README.md

* Update README.md

* Update README.md

* Update README.md

* Update README.md

* fix: Create INSTALLATION.md File (#220)

* Updated INSTALLATION.md

Node js is not needed for Docker installation

* Deleted docs folder

* Fixes #222

* Add files via upload

* Update CONTRIBUTING.md

* Update CONTRIBUTING.md

* Update PR-guidelines.md

* Update CONTRIBUTING.md

* Update issue.yml

* Bump hosted-git-info from 2.8.8 to 2.8.9

Bumps [hosted-git-info](https://github.com/npm/hosted-git-info) from 2.8.8 to 2.8.9.
- [Release notes](https://github.com/npm/hosted-git-info/releases)
- [Changelog](https://github.com/npm/hosted-git-info/blob/v2.8.9/CHANGELOG.md)
- [Commits](npm/hosted-git-info@v2.8.8...v2.8.9)

Signed-off-by: dependabot[bot] <support@github.com>

* Create linter.yml

* Update linter.yml

* Update linter.yml

* Update linter.yml

* Create test.js

* Update test.js

* Update test.js

* Update test.js

* Update test.js

* Update test.js

* Update linter.yml

* Update linter.yml

* Delete test.js

* Update linter.yml

* Update linter.yml

* Update linter.yml

* Update linter.yml

* Update linter.yml

* Update linter.yml

* Update linter.yml

* Update linter.yml

* Update linter.yml

* Update linter.yml

* Create lint.yml

* Update linter.yml

* Delete lint.yml

* Update linter.yml

* bug issue#223 resolved

* bug fix issue #223

* Delete chats.spec.js

* Delete chats.spec.dev.js

* Create chats.spec.js

* Updated branching strategy in CONTRIBUTING.md

* bug: #253 netmask bump

* bug: #253 netmask bump

* Pagination for members of organization

* feat: #263 Added i18n,  error interface library

* bugFix: #254 Bumped up node-notifier

* feat: #263 fixed error objects

* feat: #263 fixed naming conventions

* feat: #263 fixed linting

* feat: #263 fixed errors

* converted promise/callback syntax to async-await

* feat: #263 format graphql error object

* feat: #263 Fixed plural validation error handling

* feat: #263 Added util function

* feat: #263 Added hindi translations

* feat: #263 Added hindi translations

* feat: #263 Added comments for error classes

* feat: #263 Added ['hi', 'en', 'zh', 'fr', 'sp'] supported languages

* feat: #263 Packaged errors and talawa-request-context as library

* feat: #263 Packaged errors and talawa-request-context as library

* feat: #263 Fixed eslint  errors

* Update pull_request_template.md

* Feature/logging (#267)

* feat: #264 logger

* feat: #264 removed  nanoid

* feat: #264 added custom libs

* feat: #264 added custom libs

* feat: #264 removed request tracing

* feat: #264 Used custom  lib logger

* feat: #264 Compatible request tracing via logger

* feat: #264 Logging  error message

* Update Installation.md (#270)

Clarify more with the required steps for installation.

* Pagination added for posts by organisation (#273)

* pagination added for posts by org

* es lint fix

* Model and Schema update for appLanguage (#281)

* model and schema update

* language update mutation added

* language code added

* lng

* bugFix: #288 ws package upgrade (#293)

* lint issues fixed

* updated package-lock to fix lint err

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Peter Harrison <blackriver@simiya.com>
Co-authored-by: Saumya Pandey <sp160899@gmail.com>
Co-authored-by: Hrishikesh-Bhagwat <79875904+Hrishikesh-Bhagwat@users.noreply.github.com>
Co-authored-by: ShubhamBhardwaj <shubham.11901502@lpu.in>
Co-authored-by: mihdas <46824909+mihdas@users.noreply.github.com>
Co-authored-by: ssaumyaa7 <saumya4799@gmail.com>
Co-authored-by: DangaRanga <jasonblue1626@gmail.com>
Co-authored-by: Jason Gayle <55003601+DangaRanga@users.noreply.github.com>
Co-authored-by: impiyush83 <nalawadepiyush@gmail.com>
Co-authored-by: Sumitra Saksham <35868598+sumitra19jha@users.noreply.github.com>
Co-authored-by: Uttam kumar <72701081+helper-uttam@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working good first issue Good for newcomers
Projects
None yet
Development

No branches or pull requests

2 participants