Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Skip sending the proxyReq event when the expect header is present#1447

Merged
jcrugzz merged 2 commits intomasterfrom
hotfix/advisory-1486
May 17, 2020
Merged

Skip sending the proxyReq event when the expect header is present#1447
jcrugzz merged 2 commits intomasterfrom
hotfix/advisory-1486

Conversation

@jsmylnycky
Copy link
Contributor

@jsmylnyckyjsmylnycky commentedMay 15, 2020
edited
Loading

Hotfix forhttps://www.npmjs.com/advisories/1486

Expecting build error due to Node 6. Waiting for#1397 to be merged to have a clean CI build.

rgripper, AviVahl, jonny-harte, Hypnosphi, DavidCao22, bcanseco, JyotsnaC, EYHN, ianmarx, koltyakov, and 4 more reacted with thumbs up emojijimmyandrade, hamsterbacke23, serchtul, bcanseco, alokrajiv, and Max19thl reacted with eyes emoji
@alexgvozden
Copy link

will anyone merge this if it solves the issue?

jonny-harte and jimmyandrade reacted with eyes emoji

@amitmula
Copy link

Any ETA on when this is getting merged ?

jonny-harte, foestauf, danlaurent, jimmyandrade, and joseph-jordan reacted with eyes emoji

@Hypnosphi
Copy link

@indexzero@jcrugzz looks like this requires your immediate attention

jimmyandrade reacted with eyes emoji

@indexzero
Copy link
Member

My children are the only thing that requires immediate attention, sorry. Software happens during normal working hours. Didn't get to this on Friday, therefore it will be tomorrow.

Jarrett may have a moment, I have asked him.

myapos, ThomasR, tim-personio, KrisDavie, jimmyandrade, mririgoyen, uxtx, okor, and Dakkers reacted with thumbs up emojiYusreeK reacted with laugh emojimririgoyen reacted with hooray emojimririgoyen, knholland, jeonyeohun, and kmadof reacted with heart emoji

@jcrugzz
Copy link
Contributor

@jsmylnycky thanks for the work here. Will release this fix in a few

jimmyandrade reacted with thumbs up emojiuxtx reacted with heart emoji

@jcrugzzjcrugzz merged commit335aeeb intomasterMay 17, 2020
@jcrugzzjcrugzz deleted the hotfix/advisory-1486 branchMay 17, 2020 21:18
@jcrugzz
Copy link
Contributor

published as1.18.1

DavidCao22, pamit, ShunyaWatanabe, nextlevelshit, Hypnosphi, jsmylnycky, and jimmyandrade reacted with thumbs up emojiHypnosphi, jimmyandrade, and uxtx reacted with hooray emoji

@fabb
Copy link

Have you informed npm support to whitelist this version? Currently it‘s still blacklisted:https://www.npmjs.com/advisories/1486/versions
The support usually resolves such inquiries within a few hours:security@npmjs.com

nextlevelshit reacted with thumbs up emoji

@Hypnosphi
Copy link

Hypnosphi commentedMay 18, 2020
edited
Loading

@indexzero that's understandable, sorry for my wording. But thevulnerability seems reported almost 3 months ago. Do you consider adding more core maintainers as an option?

jimmyandrade reacted with thumbs up emoji

@jsmylnycky
Copy link
ContributorAuthor

@Hypnosphi If you take a look at the top of the Issues page, there's two pinned posts going back to Aug/Sept, basically looking to get more people active with the future of this project. There's been very little activity from folks willing to actually jump in and contribute tho. If it is something you're interested in doing, I suggest you take a look at those posts and leave some comments to get in touch :)

@Lucidiot
Copy link

Just out of curiosity, was the vulnerabilityactually reported to the maintainers? This would not be the first time nobody knows about the issue until the advisory goes public:sass/node-sass#2816 (comment)

@hendrikmolder
Copy link

Have you informed npm support to whitelist this version? Currently it‘s still blacklisted:https://www.npmjs.com/advisories/1486/versions
The support usually resolves such inquiries within a few hours:security@npmjs.com

They've now marked the fixed version as unaffected

sergeicodes and jimmyandrade reacted with thumbs up emoji

Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

5 more reviewers

@jkytojkytojkyto left review comments

@ryan-allyryan-allyryan-ally left review comments

@calbearoxcalbearoxcalbearox left review comments

@jimmyandradejimmyandradejimmyandrade approved these changes

@erwanriouerwanriouerwanriou approved these changes

Reviewers whose approvals may not affect merge requirements

Assignees

No one assigned

Labels

None yet

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

14 participants

@jsmylnycky@alexgvozden@amitmula@Hypnosphi@indexzero@jcrugzz@fabb@Lucidiot@hendrikmolder@jkyto@jimmyandrade@erwanriou@ryan-ally@calbearox

[8]ページ先頭

©2009-2026 Movatter.jp