String Manipulation — Studio Pro 10.24.17
Fixed — Marketplace security scan failure (CWE-494)
The Marketplace scan failed this module with a CRITICAL finding:
javascriptsource/stringmanipulation/actions/package-lock.json— The package-lock.json file contains at least 1 library whose integrity is not checked. (CWE-494)
Cause. Of the 43 entries in the lock file, only the direct dependency @stdlib/string carried resolved and integrity. All 42 transitive @stdlib packages had neither — just a version number. Without an integrity hash, npm cannot verify what it downloads, which is the supply-chain risk the scan is designed to catch.
Fix. The lock file has been regenerated against the npm registry so that every entry carries both resolved and integrity, in the modern packages block and the legacy dependencies block alike.
| Before | After | |
|---|---|---|
| Entries | 43 | 43 |
Missing integrity |
42 | 0 |
Missing resolved |
42 | 0 |
The shipped code is unchanged. Every one of the 43 pinned versions in the regenerated lock was compared against the node_modules tree that ships in this package — 43 identical, 0 mismatches, nothing added, nothing removed. The lock now describes exactly the tree it always described; it simply records the hashes as well. Integrity hashes were spot-checked against the registry for @stdlib/array@0.2.1, @stdlib/utils@0.2.1, @stdlib/types@0.3.2 and debug@2.6.9.
The codePointAt fix from 2.1 is retained.
Notes
Studio Pro 10.24.17, imports with 0 errors. 35 actions over the bundled @stdlib/string 0.2.1. Import StringManipulation.mpk via App Explorer > Import module package.