Skip to content

Conversation

@Mugunthan-Ramalingam
Copy link
Contributor

@Mugunthan-Ramalingam Mugunthan-Ramalingam commented May 9, 2024

Description

The dependabot alerts the following issues which expose the pubspec.lock file in the GitHub public repository.

  • The issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file.
  • The issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.

So, we removed the pubspec.lock file to avoid vulnerability to the repository.

Copy link
Contributor

@Yuvaraj-Gajaraj Yuvaraj-Gajaraj left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fine

@Mugunthan-Ramalingam Mugunthan-Ramalingam changed the title FLUT-885029 - [Others] Removed pub spec file FLUT-885029 - [Others] Removed pubspec.lock file because of dependabot issue May 14, 2024
Copy link
Collaborator

@VijayakumarMariappan VijayakumarMariappan left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fine

@VijayakumarMariappan VijayakumarMariappan merged commit da0920a into SyncfusionExamples:master May 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants