Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update cross-spawn to patch vulnerability; transitive dependency repo is unmaintained #10120

Closed
wants to merge 1 commit into from

Conversation

sd234678
Copy link

↪️ Pull Request

Updates the vulnerable version of cross-spawn found in node-elm-compiler; there are PRs into node-elm-compiler which fix this but haven't had maintainer attention.

💻 Examples

n/a

🚨 Test instructions

n/a

✔️ PR Todo

Unchecked items are not relevant for this PR.

  • Added/updated unit tests for this change
  • Filled out test instructions (In case there aren't any unit tests)
  • Included links to related issues/PRs
    • PR 10013 - dependabot tried to fix this

@sd234678 sd234678 force-pushed the update-cross-spawn branch from 29ac035 to a4c5c97 Compare March 20, 2025 10:56
@devongovett
Copy link
Member

I think resolutions only affect the Parcel repo itself, and they won't apply when parcel is installed in your app. You'd need to put the resolution in your own package.json as well.

@sd234678
Copy link
Author

Oh, of course, thanks. Bizarre that I didn't think of that when going down this rabbit hole. Feel free to close if this change isn't wanted at this level.

@sd234678 sd234678 closed this Mar 27, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants