Skip to content

String Manipulation

Latest

Choose a tag to compare

@bharathidas bharathidas released this 21 Aug 05:36
4e02fdc

String Manipulation — Studio Pro 10.24.17

Fixed — Marketplace security scan failure (CWE-494)

The Marketplace scan failed this module with a CRITICAL finding:

javascriptsource/stringmanipulation/actions/package-lock.json — The package-lock.json file contains at least 1 library whose integrity is not checked. (CWE-494)

Cause. Of the 43 entries in the lock file, only the direct dependency @stdlib/string carried resolved and integrity. All 42 transitive @stdlib packages had neither — just a version number. Without an integrity hash, npm cannot verify what it downloads, which is the supply-chain risk the scan is designed to catch.

Fix. The lock file has been regenerated against the npm registry so that every entry carries both resolved and integrity, in the modern packages block and the legacy dependencies block alike.

Before After
Entries 43 43
Missing integrity 42 0
Missing resolved 42 0

The shipped code is unchanged. Every one of the 43 pinned versions in the regenerated lock was compared against the node_modules tree that ships in this package — 43 identical, 0 mismatches, nothing added, nothing removed. The lock now describes exactly the tree it always described; it simply records the hashes as well. Integrity hashes were spot-checked against the registry for @stdlib/array@0.2.1, @stdlib/utils@0.2.1, @stdlib/types@0.3.2 and debug@2.6.9.

The codePointAt fix from 2.1 is retained.

Notes

Studio Pro 10.24.17, imports with 0 errors. 35 actions over the bundled @stdlib/string 0.2.1. Import StringManipulation.mpk via App Explorer > Import module package.