Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Backport 1.x] Bumps shelljs to 0.8.5 to fix CVE-2022-0144 #2512

Closed
wants to merge 1 commit into from

Conversation

ZilongX
Copy link
Collaborator

@ZilongX ZilongX commented Oct 5, 2022

Signed-off-by: Zilong Xia zilongx@amazon.com

Description

  • Resolves CVE-2022-0144 by bumping package shelljs to 0.8.5

  • Bumping up breakdowns :

  • 0.6.0 to 0.8.5

  • 0.8.3 to 0.8.5

  • 0.8.4 to 0.8.5

  • Based on shelljs's CHANGELOG , there are NO breaking changes introduced in for all version bumping

Issues Resolved

Resolved #1139

Check List

  • All tests pass
    • yarn test:jest
    • yarn test:jest_integration
    • yarn test:ftr
  • Commits are signed per the DCO using --signoff

Signed-off-by: Zilong Xia <zilongx@amazon.com>
@kavilla
Copy link
Member

kavilla commented Oct 5, 2022

Looks like duplicate here: #2511

@ananzh

@ZilongX ZilongX closed this Oct 5, 2022
@ZilongX
Copy link
Collaborator Author

ZilongX commented Oct 5, 2022

@kavilla Yes indeed, closing this one ..

@ZilongX ZilongX deleted the cve-fix-shelljs branch October 25, 2022 03:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants