-
Notifications
You must be signed in to change notification settings - Fork 3
Update dependency shelljs to ^0.8.5 [SECURITY] #15
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate
wants to merge
1
commit into
master
Choose a base branch
from
renovate/npm-shelljs-vulnerability
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
2cba2ac to
8fc2393
Compare
d91da04 to
2a36205
Compare
966ae5f to
b12c5c1
Compare
b12c5c1 to
774d406
Compare
774d406 to
4cf3fee
Compare
4cf3fee to
dc49a4b
Compare
dc49a4b to
798bf88
Compare
798bf88 to
bb0cdf2
Compare
bb0cdf2 to
932fcfe
Compare
932fcfe to
5c7276f
Compare
5c7276f to
aeb2ec7
Compare
aeb2ec7 to
d0b30d1
Compare
d0b30d1 to
2eac1f4
Compare
820cd66 to
65674c2
Compare
65674c2 to
e5afc2a
Compare
e5afc2a to
b11fcb4
Compare
b11fcb4 to
f8cc9e1
Compare
f8cc9e1 to
7376b4f
Compare
7376b4f to
5b6df4e
Compare
5b6df4e to
8983541
Compare
8983541 to
95aade0
Compare
95aade0 to
3336dbb
Compare
3336dbb to
f6415c6
Compare
f6415c6 to
10b5607
Compare
10b5607 to
62e7e6b
Compare
62e7e6b to
1bcb619
Compare
1bcb619 to
dafc5b1
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^0.7.7->^0.8.5GitHub Vulnerability Alerts
GHSA-64g7-mvw6-v9qj
Impact
Output from the synchronous version of
shell.exec()may be visible to other users on the same system. You may be affected if you executeshell.exec()in multi-user Mac, Linux, or WSL environments, or if you executeshell.exec()as the root user.Other shelljs functions (including the asynchronous version of
shell.exec()) are not impacted.Patches
Patched in shelljs 0.8.5
Workarounds
Recommended action is to upgrade to 0.8.5.
References
https://huntr.dev/bounties/50996581-c08e-4eed-a90e-c0bac082679c/
For more information
If you have any questions or comments about this advisory:
CVE-2022-0144
shelljs is vulnerable to Improper Privilege Management
Release Notes
shelljs/shelljs (shelljs)
v0.8.5Compare Source
Full Changelog
This was a small security fix for #1058.
v0.8.4Compare Source
Full Changelog
This was a small security fix for #1058.
v0.8.3Compare Source
Full Changelog
Small patch release to fix a circular dependency warning in node v14. See #973.
v0.8.2Compare Source
Full Changelog
Closed issues:
.to\(file\)does not mute STDIO output #146Merged pull requests:
v0.8.1Compare Source
Full Changelog
Closed issues:
Merged pull requests:
v0.8.0Compare Source
Full Changelog
Closed issues:
Merged pull requests:
v0.7.8Compare Source
Full Changelog
Closed issues:
ls regular-file.txt#732Merged pull requests:
-q(quiet) option topush,popd,dirsfunctions. #777 (alexreg)Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.