Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Backport the recent security fix to 3.x #74

Closed
LinusU opened this issue Jan 29, 2022 · 8 comments
Closed

Backport the recent security fix to 3.x #74

LinusU opened this issue Jan 29, 2022 · 8 comments

Comments

@LinusU
Copy link
Collaborator

LinusU commented Jan 29, 2022

We are using version 3.x of simple-get in canvas and cannot upgrade to 4.x without making it a breaking change since we still support Node.js 6.x.

@feross would it be possible to have the patch back ported to the 3.x release line?

I can submit a PR if you create a 3.x branch from abdcdb3.

Thanks!

@webmaster128
Copy link

That would be great because simple-get ^3.0.3 is a transitive dependency of other packages, like prebuild-install v5 and v6.

@smokhov
Copy link

smokhov commented Jan 31, 2022

Looks like there is a backport for 2.x.x in PR #75 , I would surmise a fix here would be very similar. I hope we get some traction here.

@DraftProducts
Copy link

I think that you can already make your pull request @LinusU, so that feross just have to approve and merge the stuff.

@feross
Copy link
Owner

feross commented Feb 1, 2022

@LinusU I gave you access to this package on GitHub and npm to help handle these security fixes. Appreciate it!

@LinusU
Copy link
Collaborator Author

LinusU commented Feb 2, 2022

I've cherry-picked the fix and released 3.1.1 and 2.8.2 🚀

@LinusU LinusU closed this as completed Feb 2, 2022
@SimenB
Copy link

SimenB commented Feb 2, 2022

Thanks! Somebody has poked the powers that be so GHSA-wpg7-2c88-r8xv get updated with the new fixed versions?

@LinusU
Copy link
Collaborator Author

LinusU commented Feb 2, 2022

Unfortunately I have no idea how to do that, would love to get to know how though ☺️

@webmaster128
Copy link

I've cherry-picked the fix and released 3.1.1 and 3.8.2 🚀

Amazing, thanks.

For the record: the last version number is a typo and needs to be 2.8.2. See also versions tab in https://www.npmjs.com/package/simple-get.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants