Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

upgrade resolve-url-loader to resolve https://www.npmjs.com/advisories/1573 #18050

Closed

Conversation

malkrad
Copy link

@malkrad malkrad commented Oct 20, 2020

There is a high severity Prototype Pollution vulnerability inside this production dependencies: resolve-url-loader.

resolve-url-loader is upgraded to 3.1.2 after the vulnerability is fixed in it.
the vulnerability inside resolve-url-loader is fixed by upgrading its production dependency: adjust-sourcemap-loader.
the vulnerability inside adjust-sourcemap-loader is fixed by replacing the vulnerable module with direct coding.

yarn.lock is updated.

This will fix #18048

@ijjk
Copy link
Member

ijjk commented Oct 20, 2020

Stats from current PR

Default Server Mode (Decrease detected ✓)
General Overall decrease ✓
vercel/next.js canary malkrad/next.js upgrade-resolve-url-loader-to-3.1.2 Change
buildDuration 12.8s 12.6s -177ms
nodeModulesSize 64.5 MB 64.3 MB -208 kB
Page Load Tests Overall decrease ⚠️
vercel/next.js canary malkrad/next.js upgrade-resolve-url-loader-to-3.1.2 Change
/ failed reqs 0 0
/ total time (seconds) 2.316 2.358 ⚠️ +0.04
/ avg req/sec 1079.48 1060.39 ⚠️ -19.09
/error-in-render failed reqs 0 0
/error-in-render total time (seconds) 1.256 1.291 ⚠️ +0.03
/error-in-render avg req/sec 1990.31 1936 ⚠️ -54.31
Client Bundles (main, webpack, commons)
vercel/next.js canary malkrad/next.js upgrade-resolve-url-loader-to-3.1.2 Change
677f882d2ed8..35e7.js gzip 11.1 kB 11.1 kB
framework.HASH.js gzip 39 kB 39 kB
main-4622877..6010.js gzip 7.34 kB 7.34 kB
webpack-e067..f178.js gzip 751 B 751 B
Overall change 58.1 kB 58.1 kB
Client Bundles (main, webpack, commons) Modern
vercel/next.js canary malkrad/next.js upgrade-resolve-url-loader-to-3.1.2 Change
677f882d2ed8..dule.js gzip 6.94 kB 6.94 kB
framework.HA..dule.js gzip 39 kB 39 kB
main-e9d8820..dule.js gzip 6.32 kB 6.32 kB
webpack-07c5..dule.js gzip 751 B 751 B
Overall change 53 kB 53 kB
Legacy Client Bundles (polyfills)
vercel/next.js canary malkrad/next.js upgrade-resolve-url-loader-to-3.1.2 Change
polyfills-4b..e242.js gzip 31 kB 31 kB
Overall change 31 kB 31 kB
Client Pages
vercel/next.js canary malkrad/next.js upgrade-resolve-url-loader-to-3.1.2 Change
_app-9a0b9e1..b37e.js gzip 1.28 kB 1.28 kB
_error-ed1b0..8fbd.js gzip 3.44 kB 3.44 kB
hooks-89731c..c609.js gzip 887 B 887 B
index-17468f..5d83.js gzip 227 B 227 B
link-89ad9e7..25bb.js gzip 1.34 kB 1.34 kB
routerDirect..924c.js gzip 284 B 284 B
withRouter-7..c13d.js gzip 284 B 284 B
Overall change 7.74 kB 7.74 kB
Client Pages Modern
vercel/next.js canary malkrad/next.js upgrade-resolve-url-loader-to-3.1.2 Change
_app-75d3a82..dule.js gzip 625 B 625 B
_error-4469a..dule.js gzip 2.29 kB 2.29 kB
hooks-cbf13f..dule.js gzip 387 B 387 B
index-b9a643..dule.js gzip 226 B 226 B
link-aeb707b..dule.js gzip 1.29 kB 1.29 kB
routerDirect..dule.js gzip 284 B 284 B
withRouter-f..dule.js gzip 282 B 282 B
Overall change 5.39 kB 5.39 kB
Client Build Manifests
vercel/next.js canary malkrad/next.js upgrade-resolve-url-loader-to-3.1.2 Change
_buildManifest.js gzip 322 B 322 B
_buildManife..dule.js gzip 329 B 329 B
Overall change 651 B 651 B
Rendered Page Sizes
vercel/next.js canary malkrad/next.js upgrade-resolve-url-loader-to-3.1.2 Change
index.html gzip 1 kB 1 kB
link.html gzip 1.01 kB 1.01 kB
withRouter.html gzip 995 B 995 B
Overall change 3.01 kB 3.01 kB

Serverless Mode (Decrease detected ✓)
General Overall decrease ✓
vercel/next.js canary malkrad/next.js upgrade-resolve-url-loader-to-3.1.2 Change
buildDuration 14.2s 14.1s -85ms
nodeModulesSize 64.5 MB 64.3 MB -208 kB
Client Bundles (main, webpack, commons)
vercel/next.js canary malkrad/next.js upgrade-resolve-url-loader-to-3.1.2 Change
677f882d2ed8..35e7.js gzip 11.1 kB 11.1 kB
framework.HASH.js gzip 39 kB 39 kB
main-4622877..6010.js gzip 7.34 kB 7.34 kB
webpack-e067..f178.js gzip 751 B 751 B
Overall change 58.1 kB 58.1 kB
Client Bundles (main, webpack, commons) Modern
vercel/next.js canary malkrad/next.js upgrade-resolve-url-loader-to-3.1.2 Change
677f882d2ed8..dule.js gzip 6.94 kB 6.94 kB
framework.HA..dule.js gzip 39 kB 39 kB
main-e9d8820..dule.js gzip 6.32 kB 6.32 kB
webpack-07c5..dule.js gzip 751 B 751 B
Overall change 53 kB 53 kB
Legacy Client Bundles (polyfills)
vercel/next.js canary malkrad/next.js upgrade-resolve-url-loader-to-3.1.2 Change
polyfills-4b..e242.js gzip 31 kB 31 kB
Overall change 31 kB 31 kB
Client Pages
vercel/next.js canary malkrad/next.js upgrade-resolve-url-loader-to-3.1.2 Change
_app-9a0b9e1..b37e.js gzip 1.28 kB 1.28 kB
_error-ed1b0..8fbd.js gzip 3.44 kB 3.44 kB
hooks-89731c..c609.js gzip 887 B 887 B
index-17468f..5d83.js gzip 227 B 227 B
link-89ad9e7..25bb.js gzip 1.34 kB 1.34 kB
routerDirect..924c.js gzip 284 B 284 B
withRouter-7..c13d.js gzip 284 B 284 B
Overall change 7.74 kB 7.74 kB
Client Pages Modern
vercel/next.js canary malkrad/next.js upgrade-resolve-url-loader-to-3.1.2 Change
_app-75d3a82..dule.js gzip 625 B 625 B
_error-4469a..dule.js gzip 2.29 kB 2.29 kB
hooks-cbf13f..dule.js gzip 387 B 387 B
index-b9a643..dule.js gzip 226 B 226 B
link-aeb707b..dule.js gzip 1.29 kB 1.29 kB
routerDirect..dule.js gzip 284 B 284 B
withRouter-f..dule.js gzip 282 B 282 B
Overall change 5.39 kB 5.39 kB
Client Build Manifests
vercel/next.js canary malkrad/next.js upgrade-resolve-url-loader-to-3.1.2 Change
_buildManifest.js gzip 322 B 322 B
_buildManife..dule.js gzip 329 B 329 B
Overall change 651 B 651 B
Serverless bundles
vercel/next.js canary malkrad/next.js upgrade-resolve-url-loader-to-3.1.2 Change
_error.js 1.06 MB 1.06 MB
404.html 4.34 kB 4.34 kB
hooks.html 3.92 kB 3.92 kB
index.js 1.06 MB 1.06 MB
link.js 1.1 MB 1.1 MB
routerDirect.js 1.1 MB 1.1 MB
withRouter.js 1.1 MB 1.1 MB
Overall change 5.42 MB 5.42 MB
Commit: 2336dc1

@matamatanot
Copy link
Contributor

#18064
Probably, this is already been resolved.

@timneutkens
Copy link
Member

Going to close this as the change has already landed in #18064. Thanks for the PR!

@vercel vercel locked as resolved and limited conversation to collaborators Jan 29, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

upgrade resolve-url-loader to 3.1.2 to resolve Prototype Pollution vulnerability
5 participants