Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

npm audio security report, sync-exec, dependency of grunt-shell-spawn #42

Closed
jeking3 opened this issue Jan 24, 2019 · 3 comments
Closed

Comments

@jeking3
Copy link
Owner

jeking3 commented Jan 24, 2019

This can be resolved by following the instructions at https://www.npmjs.com/advisories/310

root@efc557466b90:/thrift/src/lib/js# npm audit

                       === npm audit security report ===


                                 Manual Review
             Some vulnerabilities require your attention to resolve

          Visit https://go.npm.me/audit-guide for additional guidance


  Moderate        Tmp files readable by other users

  Package         sync-exec

  Patched in      No patch available

  Dependency of   grunt-shell-spawn [dev]

  Path            grunt-shell-spawn > sync-exec

  More info       https://nodesecurity.io/advisories/310

found 1 moderate severity vulnerability in 2788 scanned packages
  1 vulnerability requires manual review. See the full report for details.
@mgs255
Copy link
Collaborator

mgs255 commented Jan 26, 2019

I pushed 0.3.12 which should fix this.

@mgs255 mgs255 closed this as completed Jan 26, 2019
@mgs255
Copy link
Collaborator

mgs255 commented Jan 26, 2019

@jeking3 Created the release. I completely neglected to do this for the previous versions I pushed to NPM. Thanks for the heads up!

@jeking3
Copy link
Owner Author

jeking3 commented Jan 26, 2019

No problem - npm doesn't seem to care but I think it would be smarter if they only worked on tags. However that's their call.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants