Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

extract-zip has a dependency to mkdir@0.5.2, that has a dependency to minimist@0.0.8 which has a security issue #254

Closed
andreasmarkussen opened this issue Mar 15, 2020 · 4 comments
Assignees
Labels

Comments

@andreasmarkussen
Copy link

andreasmarkussen commented Mar 15, 2020

Chromedriver depends on extract-zip@1.6.7, which has a security problem.

Extract-zip has a dependency on mkdir@0.5.2, that has a dependency on minimist@0.0.8 which has a security issue

The problem is not easy to fix since extract-zip is not maintained.

The fix should be that someone should take over extract-zip and ensure that it is up to date.

Does anyone have suggestions to how to cope with a situation like this?

@dmarczydlo
Copy link

From security reason are you planning to update minimist dependencies?

@andrewiggins
Copy link

extract-zip has been updated: max-mapper/extract-zip#88

@giggio
Copy link
Owner

giggio commented Apr 4, 2020

I just updated and released a fix.

@giggio giggio closed this as completed Apr 4, 2020
@giggio giggio self-assigned this Apr 4, 2020
@giggio giggio added the bug label Apr 4, 2020
@lock
Copy link

lock bot commented Apr 15, 2020

This thread has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@lock lock bot locked as resolved and limited conversation to collaborators Apr 15, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants