Update dependency shelljs to ^0.10.0 [SECURITY]#15
Open
renovate[bot] wants to merge 1 commit intomasterfrom
Open
Update dependency shelljs to ^0.10.0 [SECURITY]#15renovate[bot] wants to merge 1 commit intomasterfrom
renovate[bot] wants to merge 1 commit intomasterfrom
Conversation
2cba2ac to
8fc2393
Compare
d91da04 to
2a36205
Compare
966ae5f to
b12c5c1
Compare
b12c5c1 to
774d406
Compare
774d406 to
4cf3fee
Compare
4cf3fee to
dc49a4b
Compare
dc49a4b to
798bf88
Compare
798bf88 to
bb0cdf2
Compare
bb0cdf2 to
932fcfe
Compare
932fcfe to
5c7276f
Compare
5c7276f to
aeb2ec7
Compare
aeb2ec7 to
d0b30d1
Compare
d0b30d1 to
2eac1f4
Compare
7739c35 to
30dac10
Compare
30dac10 to
8749eff
Compare
8749eff to
1ba59a3
Compare
35057ef to
ca3bd60
Compare
ca3bd60 to
0e27a33
Compare
0e27a33 to
596526c
Compare
596526c to
4e3ea5b
Compare
4e3ea5b to
2dc5436
Compare
be43c9b to
39f05e3
Compare
39f05e3 to
d480ef5
Compare
d480ef5 to
abfe94c
Compare
abfe94c to
6fc010f
Compare
6fc010f to
8cc0c51
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^0.7.7→^0.10.0GitHub Vulnerability Alerts
GHSA-64g7-mvw6-v9qj
Impact
Output from the synchronous version of
shell.exec()may be visible to other users on the same system. You may be affected if you executeshell.exec()in multi-user Mac, Linux, or WSL environments, or if you executeshell.exec()as the root user.Other shelljs functions (including the asynchronous version of
shell.exec()) are not impacted.Patches
Patched in shelljs 0.8.5
Workarounds
Recommended action is to upgrade to 0.8.5.
References
https://huntr.dev/bounties/50996581-c08e-4eed-a90e-c0bac082679c/
For more information
If you have any questions or comments about this advisory:
CVE-2022-0144
shelljs is vulnerable to Improper Privilege Management
Release Notes
shelljs/shelljs (shelljs)
v0.10.0Compare Source
What's Changed
New Contributors
Full Changelog: shelljs/shelljs@v0.9.2...v0.10.0
v0.9.2Compare Source
What's Changed
Full Changelog: shelljs/shelljs@v0.9.1...v0.9.2
v0.9.1Compare Source
What's Changed
Full Changelog: shelljs/shelljs@v0.9.0...v0.9.1
v0.9.0Compare Source
What's Changed
sedwith newlines in #949fataloption toexec()function by @WesCossick in #961New Contributors
Full Changelog: shelljs/shelljs@v0.8.5...v0.9.0
v0.8.5Compare Source
Full Changelog
This was a small security fix for #1058.
v0.8.4Compare Source
Full Changelog
This was a small security fix for #1058.
v0.8.3Compare Source
Full Changelog
Small patch release to fix a circular dependency warning in node v14. See #973.
v0.8.2Compare Source
Full Changelog
Closed issues:
.to\(file\)does not mute STDIO output #146Merged pull requests:
v0.8.1Compare Source
Full Changelog
Closed issues:
Merged pull requests:
v0.8.0Compare Source
Full Changelog
Closed issues:
Merged pull requests:
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.