Skip to content

Commit d7f6f61

Browse files
authored
Upgrade extract-zip to address vulnerability (#6845)
* Upgrade extract-zip to address vulnerability Versions of extract-zip before `1.6.8` depended on a vulnerable version of `minimist` via `mkdirp`: max-mapper/extract-zip#85 (comment) Minimist vulnerability: https://app.snyk.io/vuln/SNYK-JS-MINIMIST-559764 * Update Yarn lockfile
1 parent ee74c01 commit d7f6f61

File tree

2 files changed

+11
-25
lines changed

2 files changed

+11
-25
lines changed

cli/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,7 @@
4646
"eventemitter2": "4.1.2",
4747
"execa": "1.0.0",
4848
"executable": "4.1.1",
49-
"extract-zip": "1.6.7",
49+
"extract-zip": "1.7.0",
5050
"fs-extra": "8.1.0",
5151
"getos": "3.1.4",
5252
"is-ci": "2.0.0",

yarn.lock

Lines changed: 10 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -8281,7 +8281,7 @@ [email protected]:
82818281
resolved "https://registry.yarnpkg.com/concat-map/-/concat-map-0.0.1.tgz#d8a96bd77fd68df7793a73036a3ba0d5405d477b"
82828282
integrity sha1-2Klr13/Wjfd5OnMDajug1UBdR3s=
82838283

8284-
concat-stream@1.6.2, concat-stream@^1.4.7, concat-stream@^1.5.0, concat-stream@^1.5.2, concat-stream@^1.6.0, concat-stream@^1.6.1, concat-stream@~1.6.0:
8284+
concat-stream@^1.4.7, concat-stream@^1.5.0, concat-stream@^1.5.2, concat-stream@^1.6.0, concat-stream@^1.6.1, concat-stream@^1.6.2, concat-stream@~1.6.0:
82858285
version "1.6.2"
82868286
resolved "https://registry.yarnpkg.com/concat-stream/-/concat-stream-1.6.2.tgz#904bdf194cd3122fc675c77fc4ac3d4ff0fd1a34"
82878287
integrity sha512-27HBghJxjiZtIk3Ycvn/4kbJk/1uZuJFfuPEns6LaEvpvG1f0hTea8lilrouyo9mVc2GWdcEZ8OLoGmSADlrCw==
@@ -11089,14 +11089,14 @@ [email protected]:
1108911089
webpack-sources "^1.1.0"
1109011090

1109111091
[email protected], extract-zip@^1.0.3, extract-zip@^1.6.6:
11092-
version "1.6.7"
11093-
resolved "https://registry.yarnpkg.com/extract-zip/-/extract-zip-1.6.7.tgz#a840b4b8af6403264c8db57f4f1a74333ef81fe9"
11094-
integrity sha1-qEC0uK9kAyZMjbV/Txp0Mz74H+k=
11092+
version "1.7.0"
11093+
resolved "https://registry.yarnpkg.com/extract-zip/-/extract-zip-1.7.0.tgz#556cc3ae9df7f452c493a0cfb51cc30277940927"
11094+
integrity sha512-xoh5G1W/PB0/27lXgMQyIhP5DSY/LhoCsOyZgb+6iMmRtCwVBo55uKaMoEYrDCKQhWvqEip5ZPKAc6eFNyf/MA==
1109511095
dependencies:
11096-
concat-stream "1.6.2"
11097-
debug "2.6.9"
11098-
mkdirp "0.5.1"
11099-
yauzl "2.4.1"
11096+
concat-stream "^1.6.2"
11097+
debug "^2.6.9"
11098+
mkdirp "^0.5.4"
11099+
yauzl "^2.10.0"
1110011100

1110111101
1110211102
version "1.3.0"
@@ -11235,13 +11235,6 @@ [email protected], fd-slicer@~1.1.0:
1123511235
dependencies:
1123611236
pend "~1.2.0"
1123711237

11238-
fd-slicer@~1.0.1:
11239-
version "1.0.1"
11240-
resolved "https://registry.yarnpkg.com/fd-slicer/-/fd-slicer-1.0.1.tgz#8b5bcbd9ec327c5041bf9ab023fd6750f1177e65"
11241-
integrity sha1-i1vL2ewyfFBBv5qwI/1nUPEXfmU=
11242-
dependencies:
11243-
pend "~1.2.0"
11244-
1124511238
fecha@^2.3.3:
1124611239
version "2.3.3"
1124711240
resolved "https://registry.yarnpkg.com/fecha/-/fecha-2.3.3.tgz#948e74157df1a32fd1b12c3a3c3cdcb6ec9d96cd"
@@ -16857,7 +16850,7 @@ [email protected]:
1685716850
resolved "https://registry.yarnpkg.com/mkdirp/-/mkdirp-0.3.0.tgz#1bbf5ab1ba827af23575143490426455f481fe1e"
1685816851
integrity sha1-G79asbqCevI1dRQ0kEJkVfSB/h4=
1685916852

16860-
[email protected], [email protected], "mkdirp@>=0.5 0", mkdirp@^0.5.0, mkdirp@^0.5.1, mkdirp@^0.5.3, mkdirp@~0.5.0, mkdirp@~0.5.1:
16853+
[email protected], [email protected], "mkdirp@>=0.5 0", mkdirp@^0.5.0, mkdirp@^0.5.1, mkdirp@^0.5.3, mkdirp@^0.5.4, mkdirp@~0.5.0, mkdirp@~0.5.1:
1686116854
version "0.5.4"
1686216855
resolved "https://registry.yarnpkg.com/mkdirp/-/mkdirp-0.5.4.tgz#fd01504a6797ec5c9be81ff43d204961ed64a512"
1686316856
integrity sha512-iG9AK/dJLtJ0XNgTuDbSyNS3zECqDlAhnQW4CsNxBG3LQJBbHmRX1egw39DmtOdCAqY+dKXV+sgPgilNWUKMVw==
@@ -25413,21 +25406,14 @@ yargs@~3.27.0:
2541325406
window-size "^0.1.2"
2541425407
y18n "^3.2.0"
2541525408

25416-
25409+
[email protected], yauzl@^2.10.0:
2541725410
version "2.10.0"
2541825411
resolved "https://registry.yarnpkg.com/yauzl/-/yauzl-2.10.0.tgz#c7eb17c93e112cb1086fa6d8e51fb0667b79a5f9"
2541925412
integrity sha1-x+sXyT4RLLEIb6bY5R+wZnt5pfk=
2542025413
dependencies:
2542125414
buffer-crc32 "~0.2.3"
2542225415
fd-slicer "~1.1.0"
2542325416

25424-
25425-
version "2.4.1"
25426-
resolved "https://registry.yarnpkg.com/yauzl/-/yauzl-2.4.1.tgz#9528f442dab1b2284e58b4379bb194e22e0c4005"
25427-
integrity sha1-lSj0QtqxsihOWLQ3m7GU4i4MQAU=
25428-
dependencies:
25429-
fd-slicer "~1.0.1"
25430-
2543125417
2543225418
version "0.1.2"
2543325419
resolved "https://registry.yarnpkg.com/yeast/-/yeast-0.1.2.tgz#008e06d8094320c372dbc2f8ed76a0ca6c8ac419"

0 commit comments

Comments
 (0)