Comments (6)
our dependency on socks/ip comes through npm. npm bundles their dependencies, so there is nothing we can do until there is an npm release that resolves the issue. once that happens, our dependency on npm is defined as a range, so anyone can use the latest npm version as soon as it is available without any change from our team. we will likely tighten our supported range to force the update, but no one should be blocked by our change being released.
from semantic-release.
For what it's worth, the vulnerable code does not appear to be used by socks
: npm/cli#7216 (comment)
It is therefore not used by npm
or semantic-release
. I know a lot of people just want the audit warnings to go away, and I get that, but if you're genuinely concerned that semantic-release
is exploitable, I think the answer is a solid "No". (I wouldn't expect an SSRF to affect semantic-release anyway, but the vulnerable code doesn't even get executed, apparently.)
from semantic-release.
FYI - socks
removed ip
from 2.7.3
https://github.com/JoshGlazebrook/socks/releases/tag/2.7.3 What's the ETA for this patch? Thank you.
from semantic-release.
npm has updated their dependency here to reference ip 2.0.1 - npm/cli#7242. So, now can we expect a patch release with updated dependencies ?
from semantic-release.
npm has updated their dependency here to reference ip 2.0.1 - npm/cli#7242. So, now can we expect a patch release with updated dependencies ?
see #3202 (comment). there is nothing we can do until there is a new release of npm. even so, there is no risk other than it being reported by whatever tool you happen to be using.
from semantic-release.
It looks like npm package has now released a new version https://github.com/npm/cli/blob/latest/CHANGELOG.md
from semantic-release.
Related Issues (20)
- moving release.config.js to .config folder not reading configuration correctly. version 23.0.0 HOT 1
- ASIAN TECHNOLOGY AGENCY
- Semantic-release does not re-run on runs that failed post-prepare due to tag being there HOT 4
- moving release.config.js to .config folder not reading configuration correctly. version 23.0.0 HOT 1
- Any ability to trigger using self defined types
- 403 Forbidden Error When Publishing via GitHub Actions
- p.stdin.end is not a function. (In 'p.stdin.end()', 'p.stdin.end' is Infinity) HOT 1
- Issue with commit type "chore(deps):", not ending up in CHANGELOG.MD HOT 2
- TypeError: ((intermediate value) || (intermediate value)) is not a function from commit-analyzer HOT 1
- Semantic-Release can't access to Azure DevOps OnPrem server Git - fatal: Authentication failed
- JSR suggestion HOT 4
- Add plugin semantic-release-hackage
- bad substitution when using nextRelease.version or nextRelease.notes
- fatal: tag already exists HOT 5
- Fetch branches in parallel HOT 1
- Pre-release "counter" not incrementing HOT 6
- Unexpected Minor Version Bump in Beta Release Sequence HOT 9
- Missing Release Notes HOT 1
- Publishing a GitHub release & triggering another workflow HOT 2
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from semantic-release.