Update dependency shelljs to v0.8.5 [SECURITY] #54
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.3.0
->0.8.5
GitHub Vulnerability Alerts
GHSA-64g7-mvw6-v9qj
Impact
Output from the synchronous version of
shell.exec()
may be visible to other users on the same system. You may be affected if you executeshell.exec()
in multi-user Mac, Linux, or WSL environments, or if you executeshell.exec()
as the root user.Other shelljs functions (including the asynchronous version of
shell.exec()
) are not impacted.Patches
Patched in shelljs 0.8.5
Workarounds
Recommended action is to upgrade to 0.8.5.
References
https://huntr.dev/bounties/50996581-c08e-4eed-a90e-c0bac082679c/
For more information
If you have any questions or comments about this advisory:
CVE-2022-0144
shelljs is vulnerable to Improper Privilege Management
Release Notes
shelljs/shelljs
v0.8.5
Compare Source
This was a small security fix for #1058.
v0.8.4
Compare Source
Small patch release to fix a circular dependency warning in node v14. See #973.
v0.8.3
Compare Source
Full Changelog
Closed issues:
.to\(file\)
does not mute STDIO output #146Merged pull requests:
v0.8.2
Compare Source
Full Changelog
Closed issues:
Merged pull requests:
v0.8.1
Compare Source
Full Changelog
Closed issues:
Merged pull requests:
v0.8.0
Compare Source
Full Changelog
Closed issues:
ls regular-file.txt
#732Merged pull requests:
-q
(quiet) option topush
,popd
,dirs
functions. #777 (alexreg)v0.7.8
Compare Source
Full Changelog
Closed issues:
open
? #692Merged pull requests:
v0.7.7
Compare Source
Full Changelog
Closed issues:
Merged pull requests:
options
argument #663 (gkalpak)v0.7.6
Compare Source
Full Changelog
Closed issues:
common.error\(\)
to optionally not insert a prefix and optionally not print to console #523\1
for match groups #507exec
gets stuck on my Debian box #51Merged pull requests:
v0.7.5
Compare Source
Full Changelog
Closed issues:
plugin.error\(\)
to take an options parameter #522cp
is different between0.6.0
and0.7.4
#517Merged pull requests:
v0.7.4
Compare Source
Full Changelog
Closed issues:
Merged pull requests:
v0.7.3
Compare Source
Full Changelog
Closed issues:
Merged pull requests:
v0.7.2
Compare Source
Full Changelog
Closed issues:
cp
work incorrectly when folder name contains '@' #463Merged pull requests:
v0.7.1
Compare Source
Full Changelog
Closed issues:
Merged pull requests:
npm run gendocs
command #455 (nfischer)shell
option #449 (nfischer)v0.7.0
Compare Source
Full Changelog
Closed issues:
shjs
#388cp
does not overwrite files by default #210exec\(...\).to\(file\)
should work #154exec
#92exec\(\)
to use bash by default #281Merged pull requests:
Configuration
📅 Schedule: "" (UTC).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by WhiteSource Renovate. View repository job log here.