Skip to content

Conversation

sgerrand
Copy link
Contributor

@sgerrand sgerrand commented Apr 8, 2022

The commitzen package has not been updated since 7 May 2021 which means that numerous security patches haven't been released as new package versions.

This change forces a version on minimist which is not vulnerable to CVE-2021-44906.

See this following security advisory for more information:
GHSA-xvch-5gv4-984h

The commitzen package has not been updated since 7 May 2021
(https://github.com/commitizen/cz-cli/tree/v4.2.4) which means that
numerous security patches haven't been released as new package versions.

This change forces a version on `minimist` which is not vulnerable to
CVE-2021-44906.

See this following security advisory for more information:
GHSA-xvch-5gv4-984h
@sgerrand sgerrand added dependencies Pull requests that update a dependency file security labels Apr 8, 2022
@sgerrand sgerrand requested a review from a team as a code owner April 8, 2022 09:25
@sgerrand sgerrand requested a review from shaundon April 8, 2022 09:26
@lapa182 lapa182 merged commit 81b934d into main Apr 8, 2022
@lapa182 lapa182 deleted the CVE-2021-44906 branch April 8, 2022 09:26
@github-actions
Copy link

github-actions bot commented Apr 8, 2022

🎉 This PR is included in version 1.9.5 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file released security
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants