This repository has been archived by the owner on Jul 15, 2023. It is now read-only.
Upgrade npm-run-all. Fixes compromised transitive dependency #657
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
PR checklist
Overview of change:
This PR bumps
npm-run-all
that had compromised transitive dependency in version4.1.3
to4.1.5
that uses alternative package and do not contains compromised packages.Please see:
https://www.npmjs.com/advisories/737
mysticatea/npm-run-all#150
dominictarr/event-stream#116
Is there anything you'd like reviewers to focus on?
This dependency is listed indevDependencies
section and6.0.0-beta
installations may install compromised dependency, but should not be used if no other dependencies in project will requireevent-stream
I've remembered that removing
devDependencies
is part of build processhttps://github.com/Microsoft/tslint-microsoft-contrib/blob/4b911106ba4efa13996f05ada4a2ec7450330bc1/package.json#L60
https://github.com/Microsoft/tslint-microsoft-contrib/blob/4b911106ba4efa13996f05ada4a2ec7450330bc1/build-tasks/generate-package-json-for-npm.js#L8
So only developers of this package are affected.