-
Notifications
You must be signed in to change notification settings - Fork 31.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Harden macOS postinstall script #57660
Comments
How can we reproduce? |
@sdavids Can you provide CWE and CVSS for this? |
I am unsure want you want. It is a simple change, significantly improving the status quo. Yes, most Macs are used by a single person, so they will not be affected by this change. |
|
sdavids
added a commit
to sdavids/node
that referenced
this issue
Mar 30, 2025
Fixes: nodejs#57660 Fixes: nodejs#57548. Signed-off-by: Sebastian Davids <sdavids@gmx.de>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Version
v22.14.0
Platform
Subsystem
No response
What steps will reproduce the bug?
Use the installer.
How often does it reproduce? Is there a required condition?
Always
What is the expected behavior? Why is that the expected behavior?
The script is not susceptible to environment attacks.
What do you see instead?
node/tools/macos-installer/pkgbuild/npm/scripts/postinstall
Lines 4 to 5 in 0a91e98
Additional information
Shell Script Security - Environment Attacks
The text was updated successfully, but these errors were encountered: