Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

1.22.9 includes test/list-exports, reintroducing (false) malicious code flag #329

Closed
TomiTakussaari opened this issue Dec 19, 2024 · 3 comments

Comments

@TomiTakussaari
Copy link

Somehow, version 1.22.9 of resolve NPM package includes "/test/list-exports" directory, which contains, among other things, version 1.17.0 of this same library, in directory "test/list-exports/packages/tests/fixtures/resolve-1/".

This seems to reintroduce issue where different malicious code scanners identify this library as malicious, because one of those packages in that dir has name "monorepo-symlink-test".

Version 1.22.8 does not include this, and neither does 2.0.0-next.5.
Git repository does not include those files either, so not sure where they came from.

Are those files there because something strange happened during NPM publish? Perhaps they are not really needed, and could be removed?

NPM package contents in 1.22.9:

Image

NPM package contents in 1.22.8

Image
@ljharb
Copy link
Member

ljharb commented Dec 19, 2024

Thanks, will fix shortly.

@ljharb ljharb closed this as completed in fa2d718 Dec 19, 2024
@ljharb
Copy link
Member

ljharb commented Dec 19, 2024

Released as v1.22.10.

@TomiTakussaari
Copy link
Author

Thanks, scanners are happy again :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

2 participants