Commit b5febeb
chore(deps): bump yargs-parser to >=5.0.1 via npm overrides
Addresses GHSA-p9pc-299p-vxgp (CVE-2020-7608): yargs-parser prototype
pollution vulnerability in versions <= 5.0.0.
The vulnerable yargs-parser@2.4.1 was a transitive dependency pulled in
through gce-ips@1.0.2 -> yargs@4.x -> yargs-parser@^2.4.1. The gce-ips
package (latest: 1.0.2) has not shipped an update to fix this transitive
dependency, so a targeted npm override is used.
Note: gce-ips is a dev-only dependency and its index.js does not import
yargs at all (yargs is only used in the CLI binary, not the module). The
update-cidrs.ts script imports gce-ips as a module, so there is no
runtime impact from overriding yargs-parser in this chain.
Fixes Dependabot alert #18.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>1 parent 93a690e commit b5febeb
2 files changed
Lines changed: 7 additions & 4 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
51 | 51 | | |
52 | 52 | | |
53 | 53 | | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
54 | 57 | | |
55 | 58 | | |
0 commit comments