Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update micromatch dependency. #47

Closed
wants to merge 1 commit into from

Conversation

mastermatt
Copy link

Fixes: #46

micromatch v3 has multiple security vulnerabilities that were fixed with v4.

Changelog

Fixes: gulpjs#46

micromatch v3 has multiple security vunerabilities that were fixed with v4.

Changelog https://github.com/micromatch/micromatch/blob/master/CHANGELOG.md#400---2019-03-20
@mastermatt
Copy link
Author

Looks like micromatch dropped support for Node < 8. micromatch/micromatch#160
This lib needs to either do the same or drop the dep.

@doowb
Copy link
Member

doowb commented Jun 25, 2019

This update shouldn't be necessary now since we published patched versions of the affected dependencies. Take a look at this short guide on how to ensure you get those latest dependencies.

@mastermatt
Copy link
Author

mastermatt commented Jun 25, 2019

After a full rebuild, I still get these errors:

Prototype Pollution
high severity
Vulnerable module: set-value
Detailed paths
- Introduced through: my-app@0.1.0 › knex@0.17.6 › liftoff@3.1.0 › findup-sync@3.0.0 › micromatch@3.1.10 › snapdragon@0.8.2 › base@0.11.2 › cache-base@1.0.1 › set-value@2.0.1
- Introduced through: my-app@0.1.0 › knex@0.17.6 › liftoff@3.1.0 › findup-sync@3.0.0 › micromatch@3.1.10 › snapdragon@0.8.2 › base@0.11.2 › cache-base@1.0.1 › union-value@1.0.1 › set-value@2.0.1
- Introduced through: my-app@0.1.0 › knex@0.17.6 › liftoff@3.1.0 › findup-sync@3.0.0 › micromatch@3.1.10 › braces@2.3.2 › snapdragon@0.8.2 › base@0.11.2 › cache-base@1.0.1 › set-value@2.0.1
- Introduced through: my-app@0.1.0 › knex@0.17.6 › liftoff@3.1.0 › findup-sync@3.0.0 › micromatch@3.1.10 › extglob@2.0.4 › snapdragon@0.8.2 › base@0.11.2 › cache-base@1.0.1 › set-value@2.0.1
- Introduced through: my-app@0.1.0 › knex@0.17.6 › liftoff@3.1.0 › findup-sync@3.0.0 › micromatch@3.1.10 › nanomatch@1.2.13 › snapdragon@0.8.2 › base@0.11.2 › cache-base@1.0.1 › set-value@2.0.1
- Introduced through: my-app@0.1.0 › knex@0.17.6 › liftoff@3.1.0 › findup-sync@3.0.0 › micromatch@3.1.10 › braces@2.3.2 › snapdragon@0.8.2 › base@0.11.2 › cache-base@1.0.1 › union-value@1.0.1 › set-value@2.0.1
- Introduced through: my-app@0.1.0 › knex@0.17.6 › liftoff@3.1.0 › findup-sync@3.0.0 › micromatch@3.1.10 › extglob@2.0.4 › snapdragon@0.8.2 › base@0.11.2 › cache-base@1.0.1 › union-value@1.0.1 › set-value@2.0.1
- Introduced through: my-app@0.1.0 › knex@0.17.6 › liftoff@3.1.0 › findup-sync@3.0.0 › micromatch@3.1.10 › nanomatch@1.2.13 › snapdragon@0.8.2 › base@0.11.2 › cache-base@1.0.1 › union-value@1.0.1 › set-value@2.0.1
- Introduced through: my-app@0.1.0 › knex@0.17.6 › liftoff@3.1.0 › findup-sync@3.0.0 › micromatch@3.1.10 › extglob@2.0.4 › expand-brackets@2.1.4 › snapdragon@0.8.2 › base@0.11.2 › cache-base@1.0.1 › set-value@2.0.1
- Introduced through: my-app@0.1.0 › knex@0.17.6 › liftoff@3.1.0 › findup-sync@3.0.0 › micromatch@3.1.10 › extglob@2.0.4 › expand-brackets@2.1.4 › snapdragon@0.8.2 › base@0.11.2 › cache-base@1.0.1 › union-value@1.0.1 › set-value@2.0.1


Prototype Pollution
high severity
Vulnerable module: mixin-deep
Detailed paths
- Introduced through: my-app@0.1.0 › knex@0.17.6 › liftoff@3.1.0 › findup-sync@3.0.0 › micromatch@3.1.10 › snapdragon@0.8.2 › base@0.11.2 › mixin-deep@1.3.2
- Introduced through: my-app@0.1.0 › knex@0.17.6 › liftoff@3.1.0 › findup-sync@3.0.0 › micromatch@3.1.10 › braces@2.3.2 › snapdragon@0.8.2 › base@0.11.2 › mixin-deep@1.3.2
- Introduced through: my-app@0.1.0 › knex@0.17.6 › liftoff@3.1.0 › findup-sync@3.0.0 › micromatch@3.1.10 › extglob@2.0.4 › snapdragon@0.8.2 › base@0.11.2 › mixin-deep@1.3.2
- Introduced through: my-app@0.1.0 › knex@0.17.6 › liftoff@3.1.0 › findup-sync@3.0.0 › micromatch@3.1.10 › nanomatch@1.2.13 › snapdragon@0.8.2 › base@0.11.2 › mixin-deep@1.3.2
- Introduced through: my-app@0.1.0 › knex@0.17.6 › liftoff@3.1.0 › findup-sync@3.0.0 › micromatch@3.1.10 › extglob@2.0.4 › expand-brackets@2.1.4 › snapdragon@0.8.2 › base@0.11.2 › mixin-deep@1.3.2

Can you elaborate on where the patched dependencies were published?

@doowb
Copy link
Member

doowb commented Jun 25, 2019

set-value@2.0.1 and mixin-deep@1.3.2 are patched. I just realized that the tools reporting the vulnerabilities need to be updated to include those version ranges.

@mastermatt mastermatt closed this Jun 25, 2019
@mastermatt mastermatt deleted the upgrade-micromatch-dep branch June 25, 2019 15:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Please update micromatch dep to resolve security issues
2 participants