镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content

Update npm on all supported release lines to address CVE scored 9.8 in minimist package #32296

Description

@mleneveut

Is your feature request related to a problem? Please describe.
The package mkdir 0.5.1 contains a dependency to minimist 0.0.8, which has the CVE-2020-7598, scored 9.8

Describe the solution you'd like
Remove the package mkdirp or find a maintained alternative.

Others

node -v
v12.16.1

npm -v
6.13.4

list mkdirp
npm@6.13.4 /usr/lib/node_modules/npm
+-- cacache@12.0.3
| `-- mkdirp@0.5.1  deduped
+-- cmd-shim@3.0.3
| `-- mkdirp@0.5.1  deduped
+-- gentle-fs@2.3.0
| `-- mkdirp@0.5.1  deduped
+-- libcipm@4.0.7
| `-- mkdirp@0.5.1  deduped
+-- mkdirp@0.5.1
+-- move-concurrently@1.0.1
| +-- copy-concurrently@1.0.5
| | `-- mkdirp@0.5.1  deduped
| `-- mkdirp@0.5.1  deduped
+-- node-gyp@5.0.5
| `-- mkdirp@0.5.1  deduped
+-- pacote@9.5.11
| `-- mkdirp@0.5.1  deduped
`-- tar@4.4.13
  `-- mkdirp@0.5.1  deduped

Activity

  1. changed the title [-]Remove package mkdirp (obsolete since 2015) which uses minimalist 0.0.8 having CVE scored 9.8[/-] [+]Upgrade dependency mkdirp to 1.0.3 to fix CVE scored 9.8 in minimalist package[/+] on Mar 16, 2020
  2. mleneveut commented on Mar 16, 2020

    @mleneveut
    Author

    seems to have been forked and released in v1.0.3 without the minimalist deps : https://github.com/isaacs/node-mkdirp

  3. mscdex commented on Mar 16, 2020

    @mscdex
    Contributor

    This should be posted to the npm issue tracker instead.

  4. mleneveut commented on Mar 16, 2020

    @mleneveut
    Author

    I did, thx

  5. mcollina commented on Mar 16, 2020

    @mcollina
    SponsorMember

    I think we should keep this open because we'll need to issue new releases on all LTS line.

  6. sam-github commented on Mar 16, 2020

    @sam-github
    Contributor

    Can the subject be changed to something more specific, is this the plan?

    Update npm on all supported release lines to address CVE

    Right now, subjects suggests we'll be updating a package deep inside npm's deps, which I assume/hope is not the intention.

  7. mcollina commented on Mar 16, 2020

    @mcollina
    SponsorMember

    The intention should be for npm to do releases for all those lines and we'll just backport those to all lts lines

  8. added
    tsc-agendaIssues and PRs to discuss during Technical Steering Committee meetings.
    on Mar 16, 2020
  9. mcollina commented on Mar 16, 2020

    @mcollina
    SponsorMember

    cc @nodejs/tsc this is important.

  10. targos commented on Mar 16, 2020

    @targos
    Member

    I think this is not important because mkdirp doesn't use minimist in its API (only in the CLI, which is never used by npm or any of its dependencies).

  11. mcollina commented on Mar 16, 2020

    @mcollina
    SponsorMember

    It is because most vulnerability scanners are going to detect this automatically.

  12. targos commented on Mar 16, 2020

    @targos
    Member

    If we want to quickly fix this on our side, we can probably just rm -rf deps/npm/node_modules/minimist

  13. sam-github commented on Mar 16, 2020

    @sam-github
    Contributor

    I think hacking deps/npm sets a bad precedent, but given a 10.x is going out tomorrow, maybe it can update npm to the latest (assuming latest fixes this).

  14. 16 remaining items

  15. mcollina commented on Mar 19, 2020

    @mcollina
    SponsorMember

    v12.x (#32313) and v10.x (#31984) have releases due Tuesday 24th March that the necessary patch/update could be pulled into. Is that timeframe sufficient?

    I think that's sufficient.

    Are we still waiting on a new version of npm or do we just need to float a patch?

    I don't think npm has fixed it yet unfortunately.

  16. MylesBorins commented on Mar 19, 2020

    @MylesBorins
    Contributor

    npm update has landed

    npm/cli@cc3122a

    going to make a PR rn

  17. linked a pull request that will close this issuedeps: update npm to 6.14.3 #32368on Mar 19, 2020
  18. added a commit that references this issue on Mar 23, 2020
  19. mleneveut commented on Mar 26, 2020

    @mleneveut
    Author

    Hi, thanks for your quick and efficient work on this.

    Could we release a node 12.x with npm 6.14.4 which seems to fix deeper the issue ? npm/cli#1059

  20. removed
    tsc-agendaIssues and PRs to discuss during Technical Steering Committee meetings.
    on Apr 1, 2020
  21. added a commit that references this issue on Apr 1, 2020
  22. richardlau commented on Apr 9, 2020

    @richardlau
    Member

    Node.js 10.20.0, 12.16.2 and 13.12.0 were all updated to use npm 6.14.4.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    npmIssues and PRs related to the npm client dependency or the npm registry.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions