Skip to content

chore(ci): bump packages#18

Merged
svc-devtoolsbot merged 1 commit intomainfrom
ci/bump-packages
Jul 25, 2022
Merged

chore(ci): bump packages#18
svc-devtoolsbot merged 1 commit intomainfrom
ci/bump-packages

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

  • Bump package versions

@svc-devtoolsbot svc-devtoolsbot merged commit 8caeb14 into main Jul 25, 2022
@svc-devtoolsbot svc-devtoolsbot deleted the ci/bump-packages branch July 25, 2022 14:42
github-actions Bot added a commit that referenced this pull request May 4, 2026
Addresses GHSA-p9pc-299p-vxgp (CVE-2020-7608): yargs-parser prototype
pollution vulnerability in versions <= 5.0.0.

The vulnerable yargs-parser@2.4.1 was a transitive dependency pulled in
through gce-ips@1.0.2 -> yargs@4.x -> yargs-parser@^2.4.1. The gce-ips
package (latest: 1.0.2) has not shipped an update to fix this transitive
dependency, so a targeted npm override is used.

Note: gce-ips is a dev-only dependency and its index.js does not import
yargs at all (yargs is only used in the CLI binary, not the module). The
update-cidrs.ts script imports gce-ips as a module, so there is no
runtime impact from overriding yargs-parser in this chain.

Fixes Dependabot alert #18.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant