Repository navigation
Update npm on all supported release lines to address CVE scored 9.8 in minimist package #32296
Description
Activity
- changed the title
[-]Remove package mkdirp (obsolete since 2015) which uses minimalist 0.0.8 having CVE scored 9.8[/-][+]Upgrade dependency mkdirp to 1.0.3 to fix CVE scored 9.8 in minimalist package[/+]on Mar 16, 2020 seems to have been forked and released in v1.0.3 without the minimalist deps : https://github.com/isaacs/node-mkdirp
This should be posted to the npm issue tracker instead.
I did, thx
I think we should keep this open because we'll need to issue new releases on all LTS line.
Can the subject be changed to something more specific, is this the plan?
Update npm on all supported release lines to address CVE
Right now, subjects suggests we'll be updating a package deep inside npm's deps, which I assume/hope is not the intention.
The intention should be for npm to do releases for all those lines and we'll just backport those to all lts lines
- addedtsc-agendaIssues and PRs to discuss during Technical Steering Committee meetings.Issues and PRs to discuss during Technical Steering Committee meetings.
on Mar 16, 2020 cc @nodejs/tsc this is important.
I think this is not important because mkdirp doesn't use minimist in its API (only in the CLI, which is never used by npm or any of its dependencies).
It is because most vulnerability scanners are going to detect this automatically.
If we want to quickly fix this on our side, we can probably just
rm -rf deps/npm/node_modules/minimistI think hacking deps/npm sets a bad precedent, but given a 10.x is going out tomorrow, maybe it can update npm to the latest (assuming latest fixes this).
16 remaining items
v12.x (#32313) and v10.x (#31984) have releases due Tuesday 24th March that the necessary patch/update could be pulled into. Is that timeframe sufficient?
I think that's sufficient.
Are we still waiting on a new version of npm or do we just need to float a patch?
I don't think npm has fixed it yet unfortunately.
Reacted by Beth Griggs- Reacted by Jordan Harband and Matteo Collina
- linked a pull request that will close this issuedeps: update npm to 6.14.3 #32368
on Mar 19, 2020 - added 2 commits that reference this issue
on Mar 19, 2020 - added a commit that references this issue
on Mar 23, 2020 - added 2 commits that reference this issue
on Mar 24, 2020 Hi, thanks for your quick and efficient work on this.
Could we release a node 12.x with npm 6.14.4 which seems to fix deeper the issue ? npm/cli#1059
- removedtsc-agendaIssues and PRs to discuss during Technical Steering Committee meetings.Issues and PRs to discuss during Technical Steering Committee meetings.
on Apr 1, 2020 - added a commit that references this issue
on Apr 1, 2020 Node.js 10.20.0, 12.16.2 and 13.12.0 were all updated to use npm 6.14.4.
Is your feature request related to a problem? Please describe.
The package mkdir 0.5.1 contains a dependency to minimist 0.0.8, which has the CVE-2020-7598, scored 9.8
Describe the solution you'd like
Remove the package mkdirp or find a maintained alternative.
Others