Skip to content

fix(deps): resolve tmp to 0.2.7 to clear path traversal advisory - #1335

Open
sunitaprajapati89 wants to merge 1 commit into
masterfrom
fix/tmp-path-traversal-ghsa
Open

sunitaprajapati89 wants to merge 1 commit into
masterfrom
fix/tmp-path-traversal-ghsa

Conversation

@sunitaprajapati89

Copy link
Copy Markdown
Contributor

GHSA-ph9p-34f9-6g65: tmp < 0.2.6 allows path traversal via unsanitized prefix/postfix. Dev/CI tooling only (detox, changesets) — not shipped.

Adds two descriptor-scoped resolutions. detox's ^0.2.1 range already admits 0.2.7, but pinning it stops a future yarn up sliding back. external-editor's ^0.0.33 needs the override outright: caret on a 0.0.x version pins the patch, so it can never reach the 0.2.x line that carries the fix.

Both consumers verified against 0.2.7:

  • external-editor calls only tmpNameSync(fileOptions), and @changesets/cli constructs ExternalEditor with no arguments, so fileOptions is {} and nothing reaches the new prefix/postfix checks.
  • detox passes template 'detox--XXXXXX' and setGracefulCleanup(); both still exported, and the template check only requires XXXXXX to appear somewhere in the string.

Lockfile collapses to a single tmp@0.2.7 and drops os-tmpdir. Confirmed with yarn why tmp, yarn npm audit (advisory gone), yarn install --immutable, and a require-and-allocate smoke test of each consumer.

GHSA-ph9p-34f9-6g65: tmp < 0.2.6 allows path traversal via unsanitized
prefix/postfix. Dev/CI tooling only (detox, changesets) — not shipped.

Adds two descriptor-scoped resolutions. detox's ^0.2.1 range already
admits 0.2.7, but pinning it stops a future `yarn up` sliding back.
external-editor's ^0.0.33 needs the override outright: caret on a 0.0.x
version pins the patch, so it can never reach the 0.2.x line that
carries the fix.

Both consumers verified against 0.2.7:
- external-editor calls only tmpNameSync(fileOptions), and
  @changesets/cli constructs ExternalEditor with no arguments, so
  fileOptions is {} and nothing reaches the new prefix/postfix checks.
- detox passes template 'detox-<pid>-XXXXXX<ext>' and setGracefulCleanup();
  both still exported, and the template check only requires XXXXXX to
  appear somewhere in the string.

Lockfile collapses to a single tmp@0.2.7 and drops os-tmpdir. Confirmed
with yarn why tmp, yarn npm audit (advisory gone), yarn install
--immutable, and a require-and-allocate smoke test of each consumer.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant