Skip to content

Conversation

@ecraig12345
Copy link
Member

@ecraig12345 ecraig12345 commented Jan 23, 2026

#1114 switched to using npm-registry-fetch instead of the npm CLI for fetching package info. Unfortunately, due to Beachball's current Node 14 minbar, it was necessary to use an old npm-registry-fetch version, which pulls in an old tar version where a major vulnerability was recently discovered.

This PR reverts to using npm CLI for now, in the interest of providing a security fix without a major bump. (#1143 tracks reverting the revert.)

@ecraig12345 ecraig12345 force-pushed the ecraig/revert-npm-fetch branch from cb407cb to 6f6c5a6 Compare January 23, 2026 04:29
@ecraig12345 ecraig12345 merged commit f666c1e into main Jan 23, 2026
8 checks passed
@ecraig12345 ecraig12345 deleted the ecraig/revert-npm-fetch branch January 23, 2026 05:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants