Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Resolve monorepo-symlink-test vulnerable package #304

Closed
frabbiDAndT opened this issue Jun 14, 2023 · 1 comment
Closed

Resolve monorepo-symlink-test vulnerable package #304

frabbiDAndT opened this issue Jun 14, 2023 · 1 comment

Comments

@frabbiDAndT
Copy link

Grype scan is giving the following error:

NAME INSTALLED FIXED-IN TYPE VULNERABILITY SEVERITY
monorepo-symlink-test 0.0.0 npm GHSA-2jcg-qqmg-46q6 Critical

See more details:
https://snyk.io/advisor/npm-package/monorepo-symlink-test

Please fix the issue in:
https://github.com/browserify/resolve/blob/main/test/resolver/multirepo/package.json

@ljharb
Copy link
Member

ljharb commented Jun 14, 2023

It's not actually an issue with this package, altho it does mean Grype is incompetent and you shouldn't use it - the package.json has private: true, the fact that the name field is the same is irrelevant.

Duplicate of #303. Duplicate of #291. Duplicate of #288.

@ljharb ljharb closed this as not planned Won't fix, can't repro, duplicate, stale Jun 14, 2023
ljharb added a commit that referenced this issue Oct 10, 2023
…d security scanners

Fixes #319.
Fixes #318.
Fixes #317.
Fixes #314.
Closes #313.
Fixes #312.
Fixes #311.
Fixes #310.
Fixes #309.
Fixes #306.
Fixes #305.
Fixes #304.
Fixes #303.
Fixes #291.
Fixes #288.
ljharb added a commit that referenced this issue Oct 10, 2023
    Fixes #319.
    Fixes #318.
    Fixes #317.
    Fixes #314.
    Closes #313.
    Fixes #312.
    Fixes #311.
    Fixes #310.
    Fixes #309.
    Fixes #306.
    Fixes #305.
    Fixes #304.
    Fixes #303.
    Fixes #291.
    Fixes #288.
ljharb added a commit that referenced this issue Oct 10, 2023
    Fixes #319.
    Fixes #318.
    Fixes #317.
    Fixes #314.
    Closes #313.
    Fixes #312.
    Fixes #311.
    Fixes #310.
    Fixes #309.
    Fixes #306.
    Fixes #305.
    Fixes #304.
    Fixes #303.
    Fixes #291.
    Fixes #288.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

2 participants