-
Notifications
You must be signed in to change notification settings - Fork 886
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
security fix for 6.x versions #929
Comments
A small clip from a screenshot is not a bug report. Please file a proper issue with an actual description of the input that triggers the problem. |
Released 6.4.1 with this fix. I hope the npm version range checker is smart enough to see that that one isn't affected. |
@marijnh 6.4.1 shows up as affected: https://www.npmjs.com/advisories/1488/versions |
@marijnh The fix you provided for version 6.4.1 is just a change of changelog, not a real fix. Did you forgot to add the changes in commit? |
ok, 6.4.1 is now has been whitelisted in npm: https://www.npmjs.com/advisories/1488/versions |
No, it's not. That's the only effect on the master branch, since that tracks the latest version. |
@marijnh what are the chances of getting this backported for 5.5.0? While I'd prefer people to upgrade rather expecting backports for every version, the last version of It's not possible for |
Good question - looking over the dependencies, this is the version of
which was happily using I believe getting it whitelisted is done by just contacting npm support, and providing some information (how detailed that info is however I don't know) - @fabb if you could work your magic again for us for that version once/if it's released, that would be amazing. |
There's now a 5.7.4. I've sent an email to npm support, I don't know how long it'll take them to act on it. |
Yesterday my request to whitelist 6.4.1 sent to security@npmjs.com was answered after 1.5h. |
please made fix for 6.x versions not only 7.1.1+
https://www.npmjs.com/advisories/1488
The text was updated successfully, but these errors were encountered: