Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] Replace vulnerable inflight package #2418

Closed
4 tasks done
random-forest1 opened this issue Jan 31, 2025 · 2 comments
Closed
4 tasks done

[BUG] Replace vulnerable inflight package #2418

random-forest1 opened this issue Jan 31, 2025 · 2 comments
Labels
bug Something isn't working

Comments

@random-forest1
Copy link

Is there an existing issue for this?

  • I have searched the existing issues

Does this issue exist in the latest version?

  • I'm using the latest release

Describe the bug?

Hello,

Our security team has identified that the inflight package that the action uses under the hood is vulnerable and needs to be replaced with something else. In addition, that package is also deprecated. See: isaacs/inflight-DEPRECATED-DO-NOT-USE#5

I do not have enough knowledge of how the action is built to identify which dependency needs to be fixed for the above to be resolved. Maybe node-glob?

To Reproduce

Not applicable

What OS are you seeing the problem on?

ubuntu-20.04, ubuntu-latest or ubuntu-22.04

Expected behavior?

Not applicable

Relevant log output

Not applicable

Has all relevant logs been included?

  • I've included all relevant logs

Anything else?

No response

Code of Conduct

  • I agree to follow this project's Code of Conduct
@random-forest1 random-forest1 added the bug Something isn't working label Jan 31, 2025
@tj-actions-bot
Copy link
Contributor

Thanks for reporting this issue, don't forget to star this project if you haven't already to help us reach a wider audience.

@jackton1
Copy link
Member

jackton1 commented Feb 8, 2025

HI @random-forest1, since this is a peer dependency, It needs to be handled in the glob package as such, not something that would be fixed in this action

@jackton1 jackton1 closed this as not planned Won't fix, can't repro, duplicate, stale Feb 8, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

3 participants