Skip to content
This repository has been archived by the owner on Sep 2, 2022. It is now read-only.

sync-exec; 1 sync-exec vulnerability found in package-lock.json #3723

Closed
steida opened this issue Dec 18, 2018 · 3 comments
Closed

sync-exec; 1 sync-exec vulnerability found in package-lock.json #3723

steida opened this issue Dec 18, 2018 · 3 comments
Labels
bug/1-repro-available A reproduction exists and needs to be confirmed. kind/bug

Comments

@steida
Copy link

steida commented Dec 18, 2018

npm list sync-exec
este@ /Users/steida/dev/este-typescript
└─┬ [email protected]
  └─┬ [email protected]
    └─┬ [email protected]
      └── [email protected]

Should not be used imho.

@pantharshit00 pantharshit00 added the bug/1-repro-available A reproduction exists and needs to be confirmed. label Dec 18, 2018
@divyenduz
Copy link
Contributor

There is a regression in windows for npm-run (prisma/prisma#3517). We can upgrade this after this one is merged timoxley/npm-run#21

Or break the build for windows temporarily. Can you please confirm what the vulnerability is exactly and does it also affect CLI tools?

@steida
Copy link
Author

steida commented Dec 18, 2018

I think it's not severe, because it's for local web development, but I am not an expert. I would wait, this issue can help the others meanwhile.

@tianhuil
Copy link

The regression is still around. Any ETA on fixing this?

$ npm list sync-exec
[email protected]
└─┬ [email protected]
  └─┬ [email protected]
    └─┬ [email protected]
      └── [email protected]

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
bug/1-repro-available A reproduction exists and needs to be confirmed. kind/bug
Projects
None yet
Development

No branches or pull requests

6 participants