Skip to content

[GHSA-ppxp-px5q-gwqm] The npm ci command in npm 7.x and 8.x through 8.1.3...#518

Closed
p-w wants to merge 1 commit into
p-w/advisory-improvement-518from
p-w-GHSA-ppxp-px5q-gwqm
Closed

[GHSA-ppxp-px5q-gwqm] The npm ci command in npm 7.x and 8.x through 8.1.3...#518
p-w wants to merge 1 commit into
p-w/advisory-improvement-518from
p-w-GHSA-ppxp-px5q-gwqm

Conversation

@p-w
Copy link
Copy Markdown

@p-w p-w commented Jul 18, 2022

Updates

  • Affected products
  • Description
  • Source code location
  • Summary

@github-actions github-actions Bot changed the base branch from main to p-w/advisory-improvement-518 July 18, 2022 09:12
@darakian
Copy link
Copy Markdown
Contributor

Hi @p-w, looks like you forgot to fill in a package. Should this be for the npm on npmjs.org?

@p-w
Copy link
Copy Markdown
Author

p-w commented Jul 19, 2022

@darakian thanks for the feedback! Sorry, it seems that I've missed to add package ci

@darakian
Copy link
Copy Markdown
Contributor

@p-w Do you have a reference supporting that? The source repo listed on
https://www.npmjs.com/package/ci
is
https://github.com/privatenumber/ci
which would contradict the fix commit on the CVE
npm/cli@457e0ae

@p-w p-w closed this Jul 20, 2022
@github-actions github-actions Bot deleted the p-w-GHSA-ppxp-px5q-gwqm branch July 20, 2022 09:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants