Skip to content

CVE-2022-38900 fix for npm v6 #6010

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
wants to merge 41 commits into from
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
41 commits
Select commit Hold shift + click to select a range
be23b61
updated lockfile
darcyclarke Nov 14, 2022
382d72b
glob@7.2.0
darcyclarke Nov 14, 2022
9918f59
minimatch@3.0.5
darcyclarke Nov 14, 2022
f55bd65
rimraf@2.7.1
darcyclarke Nov 14, 2022
cd48946
bluebird@3.7.2
darcyclarke Nov 15, 2022
023d7e9
cacache@12.0.4
darcyclarke Nov 15, 2022
dd2811c
config-chain@1.1.13
darcyclarke Nov 15, 2022
e21b6eb
deep-equal@1.1.1
darcyclarke Nov 15, 2022
2bec581
dezalgo@1.0.4
darcyclarke Nov 15, 2022
2734851
figgy-pudding@3.5.2
darcyclarke Nov 15, 2022
720f8ae
glob@7.2.3
darcyclarke Nov 15, 2022
5f1200e
graceful-fs@4.2.10
darcyclarke Nov 15, 2022
58b74a3
is-cidr@3.1.1
darcyclarke Nov 15, 2022
4b60965
jsdom@16.7.0
darcyclarke Nov 15, 2022
8fe80a2
lock-verify@2.2.1
darcyclarke Nov 15, 2022
14c7a1a
meant@1.0.3
darcyclarke Nov 15, 2022
06d9cef
minimatch@3.1.2
darcyclarke Nov 15, 2022
1d2da35
mkdirp@0.5.6
darcyclarke Nov 15, 2022
22eda3a
node-gyp@5.1.1
darcyclarke Nov 15, 2022
b77a7f1
npm-registry-mock@1.3.2
darcyclarke Nov 15, 2022
de37398
query-string@6.14.1
darcyclarke Nov 15, 2022
196650b
qw@1.0.2
darcyclarke Nov 15, 2022
3218c16
read-package-json@2.1.2
darcyclarke Nov 15, 2022
0f5d579
request@2.88.2
darcyclarke Nov 15, 2022
43ed5c2
safe-buffer@5.2.1
darcyclarke Nov 15, 2022
31b51c5
tar-stream@2.2.0
darcyclarke Nov 15, 2022
209a79d
uuid@3.4.0
darcyclarke Nov 15, 2022
4778a8d
yaml@1.10.2
darcyclarke Nov 15, 2022
442ff7a
updated lockfile
darcyclarke Nov 14, 2022
f391ca8
chore: update expected integrity value in test
ruyadorno Dec 21, 2022
0437207
chore: should only lint source
ruyadorno Dec 21, 2022
f521320
chore: cleanup lockfile
ruyadorno Dec 21, 2022
db32f16
chore: minimatch is not a dep
ruyadorno Dec 21, 2022
8b357e5
decode-uri-component@0.2.2
ruyadorno Dec 21, 2022
d3e7eed
lock-verify@2.2.2
ruyadorno Dec 21, 2022
0a5f8d9
chore: remove verify no scoped test
ruyadorno Dec 21, 2022
ade941c
chore: remove gh legacy url test
ruyadorno Dec 21, 2022
771245f
docs: changelog for v6.14.18
ruyadorno Dec 21, 2022
04cb2c7
update AUTHORS
lukekarrys Dec 21, 2022
1314dc0
6.14.18
lukekarrys Dec 21, 2022
5a97385
update query-string re GHSA-5698-6q73-gp8h CVE-2022-38900
c3ivodujmovic Dec 31, 2022
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
6 changes: 6 additions & 0 deletions AUTHORS
Original file line number Diff line number Diff line change
Expand Up @@ -711,4 +711,10 @@ Lukas Spieß <lumaxis@github.com>
Darcy Clarke <darcyclarke@GH.local>
Jim Fisher <jameshfisher@gmail.com>
Xavier Guimard <yadd@debian.org>
Edward Thomson <ethomson@edwardthomson.com>
Attila Večerek <avecerek@zendesk.com>
Edward Thomson <ethomson@github.com>
Myles Borins <mylesborins@github.com>
Colm Bhandal <bhandalc@gmail.com>
Luke Karrys <luke@lukekarrys.com>
Ruy Adorno <ruyadorno@google.com>
57 changes: 57 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,60 @@
## 6.14.18 (2022-12-21)

### DEPENDENCIES

* [`f55bd65da`](https://github.com/npm/cli/commit/f55bd65da0da00655c4d4312b30d65160e7149a6)
`rimraf@2.7.1`
* [`cd4894696`](https://github.com/npm/cli/commit/cd4894696698f3a15bfa57eac373acd7f1121100)
`bluebird@3.7.2`
* [`023d7e96b`](https://github.com/npm/cli/commit/023d7e96b7c20be4071d3da32fd74856651eb3dd)
`cacache@12.0.4`
* [`dd2811c0b`](https://github.com/npm/cli/commit/dd2811c0b1e274dc56dd8e1f50d8b07bf1acc851)
`config-chain@1.1.1`:3
* [`e21b6ebd9`](https://github.com/npm/cli/commit/e21b6ebd9ae1a543864f9667dd141979c87b6724)
`deep-equal@1.1.1`
* [`2bec581c6`](https://github.com/npm/cli/commit/2bec581c6bd3ac622b8b46b2a13bc2e131c0bea4)
`dezalgo@1.0.4`
* [`273485157`](https://github.com/npm/cli/commit/273485157d5743a51003f91670de18e1811f9b9f)
`figgy-pudding@3.5.2`
* [`720f8ae5e`](https://github.com/npm/cli/commit/720f8ae5e120670463e1437ea201ef774ee5529b)
`glob@7.2.3`
* [`5f1200e33`](https://github.com/npm/cli/commit/5f1200e3386422b055fbbdb274580f12ca85992d)
`graceful-fs@4.2.1`:0
* [`58b74a38b`](https://github.com/npm/cli/commit/58b74a38b28aece8ae91474c48cc46dcb544e89d)
`is-cidr@3.1.1`
* [`4b609655f`](https://github.com/npm/cli/commit/4b609655f5ed554bfb2eb1de2c8a3272a7da7cfd)
`jsdom@16.7.0`
* [`14c7a1a85`](https://github.com/npm/cli/commit/14c7a1a85445bfd5277a4e4afdc31c98c5f67dac)
`meant@1.0.3`
* [`06d9cefc4`](https://github.com/npm/cli/commit/06d9cefc4e2d07ca7160272765449d46d34b0bc4)
`minimatch@3.1.2`
* [`1d2da355c`](https://github.com/npm/cli/commit/1d2da355ca7a7af1bf2d918ec5005cc820334af7)
`mkdirp@0.5.6`
* [`22eda3a26`](https://github.com/npm/cli/commit/22eda3a26cb14f1a0ab82e6eadb9132cd87e7183)
`node-gyp@5.1.1`
* [`b77a7f1b0`](https://github.com/npm/cli/commit/b77a7f1b095cf06b20817923cb0629e979a08ca5)
`npm-registry-mock@1.3.2`
* [`de37398af`](https://github.com/npm/cli/commit/de37398af08036d62a6b4eb6d475c02b0e6f1161)
`query-string@6.14.1`
* [`196650baa`](https://github.com/npm/cli/commit/196650baa43046c8db165a3130850a304cb9a8b7)
`qw@1.0.2`
* [`3218c16b5`](https://github.com/npm/cli/commit/3218c16b5041821b7f72efeb0f8c19408bbf6df1)
`read-package-json@2.1.2`
* [`0f5d57919`](https://github.com/npm/cli/commit/0f5d579197122713b9ffb2a7ee78108c3a851d49)
`request@2.88.2`
* [`43ed5c23b`](https://github.com/npm/cli/commit/43ed5c23b806d4904df83bd72854b57012f65992)
`safe-buffer@5.2.1`
* [`31b51c564`](https://github.com/npm/cli/commit/31b51c5646de729c691c2dec94f73988f6dd7d8a)
`tar-stream@2.2.0`
* [`209a79d1f`](https://github.com/npm/cli/commit/209a79d1fc5a00288f23f6e359212f6420530ed3)
`uuid@3.4.0`
* [`4778a8d95`](https://github.com/npm/cli/commit/4778a8d95680d62494035600a7240395a580c04d)
`yaml@1.10.2`
* [`8b357e558`](https://github.com/npm/cli/commit/8b357e5581a4fd4c95fcb889c4d89e1634c7c862)
`decode-uri-component@0.2.2`
* [`d3e7eed13`](https://github.com/npm/cli/commit/d3e7eed13a1109d7760e62bca639ed3ef64a0bd3)
`lock-verify@2.2.2`

## 6.14.17 (2022-04-28)

### DEPENDENCIES
Expand Down
14 changes: 14 additions & 0 deletions node_modules/@iarna/cli/LICENSE

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

152 changes: 152 additions & 0 deletions node_modules/@iarna/cli/README.md

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

109 changes: 109 additions & 0 deletions node_modules/@iarna/cli/app.js

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading