New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): update extract-zip to version 2 #5610
Conversation
extract-zip removed support for callbacks and instead uses promises. Moreover, it has TypeScript support which allows us to remove the @types/extract-zip package. This update allows downstream users to remove their installation of mkdirp, which uses a vulnerable version of minimist. For more info, see https://github.com/maxogden/extract-zip/releases/tag/v2.0.0
PTAL the CI errors. Looks like something is going wrong:
|
})); | ||
async function extractZip(zipPath, folderPath) { | ||
try { | ||
extract(zipPath, {dir: folderPath}); |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
do you need an await
here?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Right yes...
src/BrowserFetcher.js
Outdated
})); | ||
async function extractZip(zipPath, folderPath) { | ||
try { | ||
extract(zipPath, {dir: folderPath}); |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
same question here - await
?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done
Is there an approximate release date for the package containing this fix? Thanks! |
extract-zip removed support for callbacks and instead uses promises.
Moreover, it has TypeScript support which allows us to remove the
@types/extract-zip package.
This update allows downstream users to remove their installation
of mkdirp, which uses a vulnerable version of minimist.
For more info, see https://github.com/maxogden/extract-zip/releases/tag/v2.0.0