Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency shelljs to 0.8.5 [security] #8923

Merged
merged 1 commit into from
Jan 17, 2022

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jan 15, 2022

WhiteSource Renovate

This PR contains the following updates:

Package Change
shelljs 0.8.4 -> 0.8.5

GitHub Vulnerability Alerts

GHSA-64g7-mvw6-v9qj

Impact

Output from the synchronous version of shell.exec() may be visible to other users on the same system. You may be affected if you execute shell.exec() in multi-user Mac, Linux, or WSL environments, or if you execute shell.exec() as the root user.

Other shelljs functions (including the asynchronous version of shell.exec()) are not impacted.

Patches

Patched in shelljs 0.8.5

Workarounds

Recommended action is to upgrade to 0.8.5.

References

https://huntr.dev/bounties/50996581-c08e-4eed-a90e-c0bac082679c/

For more information

If you have any questions or comments about this advisory:


Configuration

📅 Schedule: "" (UTC).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, click this checkbox.

This PR has been generated by WhiteSource Renovate. View repository job log here.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Jan 15, 2022
@coveralls
Copy link

coveralls commented Jan 15, 2022

Pull Request Test Coverage Report for Build 808ae26a-382e-4d39-be3c-258380018054

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 94.13%

Totals Coverage Status
Change from base Build 38eae0db-18bc-4193-8057-69d114a8416f: 0.0%
Covered Lines: 5693
Relevant Lines: 6048

💛 - Coveralls

@renovate renovate bot force-pushed the renovate/npm-shelljs-vulnerability branch 22 times, most recently from 60b583f to b45b542 Compare January 17, 2022 02:47
@renovate renovate bot force-pushed the renovate/npm-shelljs-vulnerability branch from b45b542 to a128d40 Compare January 17, 2022 05:00
@kamilmysliwiec kamilmysliwiec merged commit 780188d into master Jan 17, 2022
@delete-merged-branch delete-merged-branch bot deleted the renovate/npm-shelljs-vulnerability branch January 17, 2022 08:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants