Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

just-scripts pulls in a dependency that is being marked as "Malicious component found" by component governance #585

Closed
vreddi opened this issue Apr 22, 2022 · 2 comments · Fixed by #748

Comments

@vreddi
Copy link

vreddi commented Apr 22, 2022

Affected component:
es5-ext
0.10.60

Security Review (CST-E)
This package prints a protest message (in support of Ukraine) upon installation, when the package is installed on a system located in or around Russia. Downgrade to 0.10.53 or an earlier version.

image

@ecraig12345
Copy link
Member

ecraig12345 commented Sep 9, 2022

Unfortunately I don't think there's a good way to fix this in just-task directly until gulpjs/undertaker#97 is merged and published, removing the es6-weak-map dep (since it's not needed in modern Node versions).

Locally I tested what would happen if I added a dep on es5-ext@0.10.53 in just-task (in a clean install with no lock file), but yarn unnecessarily resolved ^ versions of the same dep to latest.
image

So for now, the most reliable workaround is to add resolutions on the consumer's end.

@ecraig12345 ecraig12345 linked a pull request Mar 26, 2024 that will close this issue
1 task
@ecraig12345
Copy link
Member

undertaker finally released a new version, so this is fixed in just-scripts 2.3.0 and just-task 1.10.0.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants