Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Patch versions for older majors? #16

Closed
aaronjensen opened this issue Jul 12, 2019 · 8 comments
Closed

Patch versions for older majors? #16

aaronjensen opened this issue Jul 12, 2019 · 8 comments

Comments

@aaronjensen
Copy link

aaronjensen commented Jul 12, 2019

Hi there, any chance of releasing patch versions with the security fix for the older major versions? Many very popular libraries depend on ^2.0.0 or even 0.X. Thanks!

@heyimalex
Copy link

heyimalex commented Jul 12, 2019

Just for reference, here's the advisory. I saw another comment that said it'd also been patched in 2.0.1, maybe the advisory should be changed to reflect that.

@aaronjensen
Copy link
Author

the only way to watch this right now is by commenting, so I am commenting

This works too:

CleanShot 2019-07-12 at 13 43 28

@chaosZeroFive
Copy link

Unfortunately a ton of bundled modules under a ton of other modules reference v2...what is the fix?

@aaronjensen
Copy link
Author

@chaosZeroFive it sounds like 2.0.1 has the fix, but the advisory doesn't know it yet, so npm audit doesn't know it yet.

@heyimalex
Copy link

Yeah, it's definitely applied in the 2.0.1 branch. I shot an email to npm support about this, hopefully they change the criteria for the advisory.

@heyimalex
Copy link

I was just emailed back by npm, they added 2.0.1 to remediated!

@doowb
Copy link
Collaborator

doowb commented Jul 12, 2019

I was just emailed back by npm, they added 2.0.1 to remediated!

I just verified that by running npm audit on the same package I did before, this now returns 0 vulnerabilities.

@doowb doowb closed this as completed Jul 12, 2019
@philmayfield
Copy link

Greatly appreciate the fix. Just a heads up that this still shows as vulnerable in the Github Advisory Database.

GHSA-4jqc-8m5r-9rpr

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants