Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Resolve vulnerabilities in dependencies #815

Merged
merged 3 commits into from
Feb 16, 2022

Conversation

AndreyIvanov42
Copy link
Contributor

  • Bumped shelljs to 0.8.5
  • adm-zip to 0.5.9
  • fixed tests (due to changes in methods shelljs)

Tested only with mocha tests

@AndreyIvanov42 AndreyIvanov42 added the dependencies Pull requests that update a dependency file label Feb 10, 2022
@AndreyIvanov42 AndreyIvanov42 requested a review from a team February 10, 2022 07:13
@anatolybolshakov
Copy link
Contributor

@AndreyIvanov42 where are ensureStarted and ensureTool methods affected - could you please double-check that you've tested scenarios in which these methods are being used?

@AndreyIvanov42
Copy link
Contributor Author

@anatolybolshakov
I double-checked ensureStarted and ensureTool methods. They are used only in tests.
But since many methods of this library are wrappers over shelljs methods, I need to make sure that backward compatibility is not broken.

@anatolybolshakov
Copy link
Contributor

Please bump package/package-lock versions

@anatolybolshakov anatolybolshakov requested a review from a team February 15, 2022 11:30
@AndreyIvanov42 AndreyIvanov42 merged commit 82f3744 into master Feb 16, 2022
@AndreyIvanov42 AndreyIvanov42 deleted the users/v-andivanov/bump-shelljs-version branch February 16, 2022 12:44
@kriti218
Copy link

@AndreyIvanov42 When are we going to have 3.2.0 as the latest version to download? It looks like shelljs vulnerability was fixed in this PR #815 when version was updated to 0.8.5 from 8.4.

@AndreyIvanov42
Copy link
Contributor Author

@kriti218
New version is available

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants