Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Opener 1.5.1 to Opener 1.5.2 #36445

Closed
earmia opened this issue Dec 8, 2020 · 8 comments · May be fixed by Lernopus/lernopus-client#18 or safe-fleet/eventuate-tram-core-dotnet#7
Closed

Update Opener 1.5.1 to Opener 1.5.2 #36445

earmia opened this issue Dec 8, 2020 · 8 comments · May be fixed by Lernopus/lernopus-client#18 or safe-fleet/eventuate-tram-core-dotnet#7
Labels
npm Issues and PRs related to the npm client dependency or the npm registry.

Comments

@earmia
Copy link

earmia commented Dec 8, 2020

Is your feature request related to a problem? Please describe.
Opener 1.5.1 is vulnerable to code injection attacks
domenic/opener#34

Describe the solution you'd like
Update Opener 1.5.1 to Opener 1.5.2

Describe alternatives you've considered
Please describe alternative solutions or features you have considered.

@benjamingr
Copy link
Member

The only place I see opener in the Node codebase is NPM and that's already 1.5.2 I believe?

Mind pointing me to what you mean?

@earmia
Copy link
Author

earmia commented Dec 9, 2020

Hi @benjamingr, in a private instance of Sonatype the scan shows that it's located at node-v14.15.1-win-x64.zip/node-v14.15.1-win-x64/node_modules/npm/node_modules/opener/lib

It's for Node LTS 14.15.1
https://github.com/nodejs/node/blob/v14.x/deps/npm/node_modules/opener/package.json

My apologies, I didn't mention that.

@richardlau
Copy link
Member

Doesn't look like the most recent npm 6 release (#36450) contains the updated version of opener.
cc @nodejs/npm

@richardlau richardlau added the npm Issues and PRs related to the npm client dependency or the npm registry. label Dec 9, 2020
@MylesBorins
Copy link
Member

pinged the team to discuss

@earmia
Copy link
Author

earmia commented Dec 17, 2020

pinged the team to discuss

Hi @MylesBorins any updates ?

14.15.2 was released and it has opener 1.5.1, do you know when this request can be progressed ?

@MylesBorins
Copy link
Member

@armiasaied we are working on getting an npm 6 release out ASAP and I'll get that backported to all appropriate release lines and discuss with the release team about a timeline to include it. Hopefully we can get this out relateively quickly in the new year

richardlau pushed a commit that referenced this issue Dec 23, 2020
PR-URL: #36571
Fixes: #36445
Reviewed-By: Rich Trott <rtrott@gmail.com>
Reviewed-By: Myles Borins <myles.borins@gmail.com>
Reviewed-By: Michael Dawson <midawson@redhat.com>
richardlau pushed a commit that referenced this issue Dec 23, 2020
PR-URL: #36571
Fixes: #36445
Reviewed-By: Rich Trott <rtrott@gmail.com>
Reviewed-By: Myles Borins <myles.borins@gmail.com>
Reviewed-By: Michael Dawson <midawson@redhat.com>
richardlau pushed a commit that referenced this issue Dec 23, 2020
PR-URL: #36571
Fixes: #36445
Reviewed-By: Rich Trott <rtrott@gmail.com>
Reviewed-By: Myles Borins <myles.borins@gmail.com>
Reviewed-By: Michael Dawson <midawson@redhat.com>
@targos
Copy link
Member

targos commented Dec 28, 2020

The fix landed and will be in the next releases of v14/v12/v10

@targos targos closed this as completed Dec 28, 2020
@earmia
Copy link
Author

earmia commented Dec 28, 2020

Thank you All ☺️

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment