Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

colors dependecy attack through prettyjson #64

Closed
t1bb4r opened this issue Jan 10, 2022 · 0 comments · Fixed by #65
Closed

colors dependecy attack through prettyjson #64

t1bb4r opened this issue Jan 10, 2022 · 0 comments · Fixed by #65

Comments

@t1bb4r
Copy link

t1bb4r commented Jan 10, 2022

Issue:
Install run-rs in a new project would result in installing malicious package, colors > 1.4.0 (Causing infinite loop prints on your system).

Solution:
The issue has already been reported and fixed in prettyjson, a new version has not yet been published to npm.
rafeca/prettyjson#54

Once published please update prettyjson to 1.2.2 (or whatever tag will be used).

Temporary workaround:
add colors as a top level dependency npm install colors@1.4.0.

Thanks:
run-rs is awesome and a crucial part of testing in multiple projects I work on. Thank you so much @vkarpov15 for all your hard work on this!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant