Skip to content

Commit 25e5c69

Browse files
Universal: Update 'npm:minimist' due to CVE-2020-7598 & CVE-2021-44906 (#284)
* Universal: Update 'npm:minimist' due to CVE-2020-7598 & CVE-2021-44906 * add * * Update test.sh
1 parent bb1fcf9 commit 25e5c69

File tree

2 files changed

+9
-0
lines changed

2 files changed

+9
-0
lines changed

src/universal/.devcontainer/local-features/setup-user/install.sh

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -66,6 +66,10 @@ NPM_PACKAGES_LIST="ansi-regex
6666
cd /usr/local/share/nvm/versions/node/v14*/lib/node_modules/npm
6767
npm install ${NPM_PACKAGES_LIST}
6868

69+
# Temporary due to minimist: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44906 & https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7598
70+
cd /usr/local/share/nvm/versions/node/v14*/lib/node_modules/npm/node_modules/tacks
71+
npm update mkdirp
72+
6973
# Temporary: Due to https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0536 & https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0155
7074
rm -rf /usr/local/nvs/deps/node_modules/follow-redirects/*
7175
curl -sSL https://github.com/follow-redirects/follow-redirects/archive/refs/tags/v1.15.2.tar.gz | tar -xzC /tmp 2>&1

src/universal/test-project/test.sh

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -196,6 +196,11 @@ check-version-ge "got" "${gotVersion}" "12.1.0"
196196
qsVersion=$(npm ls --depth 1 --json | jq -r '.dependencies.qs.version')
197197
check-version-ge "qs" "${qsVersion}" "6.10"
198198

199+
cd /usr/local/share/nvm/versions/node/v14*/lib/node_modules/npm/node_modules/tacks
200+
201+
minimistVersion=$(npm ls --depth 1 --json | jq -r '.dependencies.mkdirp.dependencies.minimist.version')
202+
check-version-ge "minimist" "${minimistVersion}" "1.2.6"
203+
199204
ls -la /home/codespace
200205

201206
# Report result

0 commit comments

Comments
 (0)