Skip to content

Commit b5febeb

Browse files
chore(deps): bump yargs-parser to >=5.0.1 via npm overrides
Addresses GHSA-p9pc-299p-vxgp (CVE-2020-7608): yargs-parser prototype pollution vulnerability in versions <= 5.0.0. The vulnerable yargs-parser@2.4.1 was a transitive dependency pulled in through gce-ips@1.0.2 -> yargs@4.x -> yargs-parser@^2.4.1. The gce-ips package (latest: 1.0.2) has not shipped an update to fix this transitive dependency, so a targeted npm override is used. Note: gce-ips is a dev-only dependency and its index.js does not import yargs at all (yargs is only used in the CLI binary, not the module). The update-cidrs.ts script imports gce-ips as a module, so there is no runtime impact from overriding yargs-parser in this chain. Fixes Dependabot alert #18. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
1 parent 93a690e commit b5febeb

2 files changed

Lines changed: 7 additions & 4 deletions

File tree

package-lock.json

Lines changed: 4 additions & 4 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

package.json

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -51,5 +51,8 @@
5151
"depcheck": "^1.4.7",
5252
"husky": "^9.1.7",
5353
"lerna": "^9.0.7"
54+
},
55+
"overrides": {
56+
"gce-ips>yargs>yargs-parser": ">=5.0.1"
5457
}
5558
}

0 commit comments

Comments
 (0)