Revert "Bump the npm_and_yarn group across 1 directory with 4 updates"#2
Conversation
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
There was a problem hiding this comment.
Code Review
This pull request reverts several dependencies in package-lock.json, including brace-expansion, flatted, lodash, and picomatch, to earlier versions. The reviewer identified that the target versions in these reverts are still compromised by a supply chain attack and recommended further downgrading to specific safe versions for all affected packages.
| "version": "5.0.4", | ||
| "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.4.tgz", | ||
| "integrity": "sha512-h+DEnpVvxmfVefa4jFbCf5HdH5YMDXRsmKflpf1pILZWRFlTbJpxeU55nJl4Smt5HQaGzg1o6RHFPJaOqnmBDg==", |
There was a problem hiding this comment.
This revert is insufficient. The version 5.0.4 of brace-expansion is also reported to be malicious as part of a supply chain attack. Please update to the last known safe version, 5.0.1.
"version": "5.0.1",
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.1.tgz",
"integrity": "sha512-jdbG3g3Sg/nBItl/ET34p32y2Q82iX/g5fSP26gL2aE2sPfnY3a8Pj6Iiki2vU2w2tI7TzqnYy3sQ=="| "version": "1.1.12", | ||
| "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.12.tgz", | ||
| "integrity": "sha512-9T9UjW3r0UW5c1Q7GTwllptXwhvYmEzFhzMfZ9H7FQWt+uZePjZPjBP/W1ZEyZ1twGWom5/56TF4lPcqjnDHcg==", |
There was a problem hiding this comment.
This revert is insufficient. The version 1.1.12 of brace-expansion is also reported to be malicious as part of a supply chain attack. Please update to the last known safe version, 1.1.11.
"version": "1.1.11",
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.11.tgz",
"integrity": "sha512-iCuPHDFgrHX7H2vEI/5xpz07zSHB00TpugqhmYtVmMO6518mCuRMoOYFldEBl0g187ufozdaHgWKcYFb61qGiA=="| "version": "3.4.1", | ||
| "resolved": "https://registry.npmjs.org/flatted/-/flatted-3.4.1.tgz", | ||
| "integrity": "sha512-IxfVbRFVlV8V/yRaGzk0UVIcsKKHMSfYw66T/u4nTwlWteQePsxe//LjudR1AMX4tZW3WFCh3Zqa/sjlqpbURQ==", |
There was a problem hiding this comment.
This revert is insufficient. The version 3.4.1 of flatted is also reported to be malicious as part of a supply chain attack. Please update to the last known safe version, 3.3.1.
"version": "3.3.1",
"resolved": "https://registry.npmjs.org/flatted/-/flatted-3.3.1.tgz",
"integrity": "sha512-X/y8v8yXQ29sMVqf+G3J/Y2a9Y2fE4pT/3s0m3sX3Jb/zGNET/eQ3hY6d/w6qA3/p643Ie/2Uv1a/A=="| "version": "4.17.23", | ||
| "resolved": "https://registry.npmjs.org/lodash/-/lodash-4.17.23.tgz", | ||
| "integrity": "sha512-LgVTMpQtIopCi79SJeDiP0TfWi5CNEc/L/aRdTh3yIvmZXTnheWpKjSZhnvMl8iXbC1tFg9gdHHDMLoV7CnG+w==", |
There was a problem hiding this comment.
This revert is insufficient. The version 4.17.23 of lodash is also reported to be malicious as part of a supply chain attack. Please update to the last known safe version, 4.17.21.
"version": "4.17.21",
"resolved": "https://registry.npmjs.org/lodash/-/lodash-4.17.21.tgz",
"integrity": "sha512-v2kDEe57lecTulaDIuNTPy3Ry4gLGJ6Z1O3vE1krgXZNrsQ+LFTGHVxVjcXPs17LhbZVGedAJv8XZ1tvj5FvA=="| "version": "2.0.2", | ||
| "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.0.2.tgz", | ||
| "integrity": "sha512-Jt0vHyM+jmUBqojB7E1NIYadt0vI0Qxjxd2TErW94wDz+E2LAm5vKMXXwg6ZZBTHPuUlDgQHKXvjGBdfcF1ZDQ==", |
There was a problem hiding this comment.
This revert is insufficient. The version 2.0.2 of brace-expansion is also reported to be malicious as part of a supply chain attack. Please update to the last known safe version, 2.0.1.
"version": "2.0.1",
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.0.1.tgz",
"integrity": "sha512-XnAIvQ8eM+kC6aULx6wuQiwVsnzfl59ZgYAuDStV6rOAdisjWw8ffGvs2uwnM1COCj7Auh21sErkX9iaI9cOwg=="| "version": "4.0.3", | ||
| "resolved": "https://registry.npmjs.org/picomatch/-/picomatch-4.0.3.tgz", | ||
| "integrity": "sha512-5gTmgEY/sqK6gFXLIsQNH19lWb4ebPDLA4SdLP7dsWkIXHWlG66oPuVvXSGFPppYZz8ZDZq0dYYrbHfBCVUb1Q==", |
There was a problem hiding this comment.
This revert is insufficient. The version 4.0.3 of picomatch is also reported to be malicious as part of a supply chain attack. Please update to the last known safe version, 4.0.2.
"version": "4.0.2",
"resolved": "https://registry.npmjs.org/picomatch/-/picomatch-4.0.2.tgz",
"integrity": "sha512-v4pGf223mmZ2p2l2w2Yt07N2T1up2QYyA3iIe51lA2m2j2a2aR0z4uY8g2z3g3sA3sYm1vTfI422A=="| "version": "4.0.3", | ||
| "resolved": "https://registry.npmjs.org/picomatch/-/picomatch-4.0.3.tgz", | ||
| "integrity": "sha512-5gTmgEY/sqK6gFXLIsQNH19lWb4ebPDLA4SdLP7dsWkIXHWlG66oPuVvXSGFPppYZz8ZDZq0dYYrbHfBCVUb1Q==", |
There was a problem hiding this comment.
This revert is insufficient. The version 4.0.3 of picomatch is also reported to be malicious as part of a supply chain attack. Please update to the last known safe version, 4.0.2.
"version": "4.0.2",
"resolved": "https://registry.npmjs.org/picomatch/-/picomatch-4.0.2.tgz",
"integrity": "sha512-v4pGf223mmZ2p2l2w2Yt07N2T1up2QYyA3iIe51lA2m2j2a2aR0z4uY8g2z3g3sA3sYm1vTfI422A=="| "version": "4.0.3", | ||
| "resolved": "https://registry.npmjs.org/picomatch/-/picomatch-4.0.3.tgz", | ||
| "integrity": "sha512-5gTmgEY/sqK6gFXLIsQNH19lWb4ebPDLA4SdLP7dsWkIXHWlG66oPuVvXSGFPppYZz8ZDZq0dYYrbHfBCVUb1Q==", |
There was a problem hiding this comment.
This revert is insufficient. The version 4.0.3 of picomatch is also reported to be malicious as part of a supply chain attack. Please update to the last known safe version, 4.0.2.
"version": "4.0.2",
"resolved": "https://registry.npmjs.org/picomatch/-/picomatch-4.0.2.tgz",
"integrity": "sha512-v4pGf223mmZ2p2l2w2Yt07N2T1up2QYyA3iIe51lA2m2j2a2aR0z4uY8g2z3g3sA3sYm1vTfI422A=="


Reverts #1