mirror of
https://github.com/actions/setup-node.git
synced 2026-08-02 00:46:09 +00:00
fix: update brace-expansion to patch GHSA-3jxr-9vmj-r5cp (exponential-time DoS) (#1599)
* Initial plan * fix: update brace-expansion to address GHSA-3jxr-9vmj-r5cp and rebuild dist - brace-expansion 1.1.13 → 1.1.16 (GHSA-3jxr-9vmj-r5cp patched floor: 1.1.16) - brace-expansion 2.1.1 → 2.1.2 (GHSA-3jxr-9vmj-r5cp patched floor: 2.1.2) - brace-expansion 5.0.6 → 5.0.8 (GHSA-3jxr-9vmj-r5cp patched floor: 5.0.7; also fixes GHSA-mh99-v99m-4gvg) - Regenerated package-lock.json - Rebuilt dist/setup/index.js and dist/cache-save/index.js with patched dependency Closes #1596 * fix: eliminate remaining brace-expansion vulnerabilities and update license cache ## Basic validation CI fix Add `overrides` in package.json to eliminate all brace-expansion 1.x and 2.x from the dependency tree, resolving GHSA-mh99-v99m-4gvg for all packages: - `"@actions/glob": "$@actions/glob"` - forces @actions/cache to use the root @actions/glob@0.7.0 (minimatch@10.x → brace-expansion@5.0.8) instead of its bundled @actions/glob@0.6.1 (minimatch@3.x → brace-expansion@1.x) - `"glob": {"minimatch": "^10.2.5"}` - forces glob@10.x to use minimatch@10.x → brace-expansion@5.0.8 instead of minimatch@9.x → brace-expansion@2.x - `"test-exclude": "^7.0.2"` - upgrades test-exclude to a version that natively uses minimatch@10.x (instead of @3.x), removing brace-expansion@1.x from the jest coverage instrumentation path `npm audit --audit-level=high` now reports 0 vulnerabilities. ## Licensed CI fix Update .licenses/npm/ cache to match the new dependency tree: - Add: brace-expansion-5.0.8.dep.yml - Add: minimatch-10.2.6.dep.yml - Remove stale: brace-expansion-1.1.13.dep.yml (already done in prev commit) - Remove stale: brace-expansion-5.0.6.dep.yml (already done in prev commit) - Remove stale: minimatch-3.1.5.dep.yml - Remove stale: @actions/glob-0.6.1.dep.yml - Remove stale: concat-map.dep.yml - Remove stale: balanced-match-1.0.2.dep.yml Rebuild dist artifacts to include updated brace-expansion. * fix: replace brace-expansion workarounds with single override --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
This commit is contained in:
Generated
-31
@@ -1,31 +0,0 @@
|
||||
---
|
||||
name: concat-map
|
||||
version: 0.0.1
|
||||
type: npm
|
||||
summary: concatenative mapdashery
|
||||
homepage: https://github.com/substack/node-concat-map#readme
|
||||
license: other
|
||||
licenses:
|
||||
- sources: LICENSE
|
||||
text: |
|
||||
This software is released under the MIT license:
|
||||
|
||||
Permission is hereby granted, free of charge, to any person obtaining a copy of
|
||||
this software and associated documentation files (the "Software"), to deal in
|
||||
the Software without restriction, including without limitation the rights to
|
||||
use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of
|
||||
the Software, and to permit persons to whom the Software is furnished to do so,
|
||||
subject to the following conditions:
|
||||
|
||||
The above copyright notice and this permission notice shall be included in all
|
||||
copies or substantial portions of the Software.
|
||||
|
||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS
|
||||
FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR
|
||||
COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER
|
||||
IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
|
||||
CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
||||
- sources: README.markdown
|
||||
text: MIT
|
||||
notices: []
|
||||
Reference in New Issue
Block a user