New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
build(docs-infra): upgrade npm-run-all
to latest version for security
#27274
Closed
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Earlier versions may transitively depend on a malicious version of `flatmap-stream` (see dominictarr/event-stream#116). The `aio-builds-setup/` had an older version of `event-stream` (3.3.4), which did not depend on `flatmap-stream`, but upgraded it anyway.
gkalpak
added
area: build & ci
Related the build and CI infrastructure of the project
action: review
The PR is still awaiting reviews from at least one requested reviewer
comp: docs-infra
target: patch
This PR is targeted for the next patch release
labels
Nov 26, 2018
jasonaden
approved these changes
Nov 26, 2018
jasonaden
added
action: merge
The PR is ready for merge by the caretaker
and removed
action: review
The PR is still awaiting reviews from at least one requested reviewer
labels
Nov 26, 2018
You can preview c3538b0 at https://pr27274-c3538b0.ngbuilds.io/. |
jasonaden
pushed a commit
that referenced
this pull request
Nov 26, 2018
…ty (#27274) Earlier versions may transitively depend on a malicious version of `flatmap-stream` (see dominictarr/event-stream#116). The `aio-builds-setup/` had an older version of `event-stream` (3.3.4), which did not depend on `flatmap-stream`, but upgraded it anyway. PR Close #27274
jasonaden
pushed a commit
that referenced
this pull request
Nov 27, 2018
…ty (#27274) Earlier versions may transitively depend on a malicious version of `flatmap-stream` (see dominictarr/event-stream#116). The `aio-builds-setup/` had an older version of `event-stream` (3.3.4), which did not depend on `flatmap-stream`, but upgraded it anyway. PR Close #27274
FrederikSchlemmer
pushed a commit
to FrederikSchlemmer/angular
that referenced
this pull request
Jan 3, 2019
…ty (angular#27274) Earlier versions may transitively depend on a malicious version of `flatmap-stream` (see dominictarr/event-stream#116). The `aio-builds-setup/` had an older version of `event-stream` (3.3.4), which did not depend on `flatmap-stream`, but upgraded it anyway. PR Close angular#27274
ngfelixl
pushed a commit
to ngfelixl/angular
that referenced
this pull request
Jan 28, 2019
…ty (angular#27274) Earlier versions may transitively depend on a malicious version of `flatmap-stream` (see dominictarr/event-stream#116). The `aio-builds-setup/` had an older version of `event-stream` (3.3.4), which did not depend on `flatmap-stream`, but upgraded it anyway. PR Close angular#27274
This issue has been automatically locked due to inactivity. Read more about our automatic conversation locking policy. This action has been performed automatically by a bot. |
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Labels
action: merge
The PR is ready for merge by the caretaker
area: build & ci
Related the build and CI infrastructure of the project
cla: yes
target: patch
This PR is targeted for the next patch release
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Earlier versions may transitively depend on a malicious version of
flatmap-stream
(see dominictarr/event-stream#116).The
aio-builds-setup/
had an older version ofevent-stream
(3.3.4), which did not depend onflatmap-stream
, but upgraded it anyway.