Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Published npm-shrinkwrap.json pins [email protected] with vulnerable [email protected]

Open
#3,642 5 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
55/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
javascript, node.js

Research direction

Start by locating the generation process for the published npm-shrinkwrap.json and inspect how [email protected] enters the @salesforce/cli package. Reproduce a clean installation with npm ci, update the generated dependency to [email protected] or newer, and verify that tar is no longer 7.5.19 before publishing a new CLI release.

Written by the indexing model from the issue text.

Description

bug more information required

Summary

Published @salesforce/cli packages include an npm-shrinkwrap.json that pins [email protected]. That npm release bundles [email protected], which is affected by:

[email protected] bundles the fixed [email protected].

Affected releases

I confirmed the following published CLI releases contain the same vulnerable dependency chain:

Dependency path:

@salesforce/cli
└── [email protected]
    └── [email protected]

Consumer impact

Dependabot reports this as a high-severity runtime vulnerability. Consumers cannot cleanly remediate it themselves because the published CLI shrinkwrap dictates the nested npm dependency.

I tested the following approaches:

npm update npm
Root-level npm overrides
Overrides scoped beneath @salesforce/cli
Adding [email protected] as a direct dependency
Manually updating the consuming repository's package-lock.json
None fixes a clean installation. npm ci follows the CLI's published shrinkwrap and reinstalls [email protected] and [email protected]. A manual lockfile edit can make dependency scanning appear fixed while leaving the installed package vulnerable.

Requested fix

Please update the CLI's generated shrinkwrap to use [email protected] or newer and publish a new @salesforce/cli release.

Expected dependency path:

Thank you!

Dominant language
No language data
Stars
571
Forks
80
Avg merge
2d 21h
Merged PRs (30d)
3

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from forcedotcom/cli

All issues in forcedotcom/cli

Similar issues

More Build System issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.