Vulnerability in downstream package
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 38/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Stale
- Tech stack
- typescript
Research direction
Start in app/lib/tfcommand.ts around line 691 and inspect how clipboardy is used. Upgrade clipboardy to 4.0.0, account for its changed API at that call site, and verify that the CLI still copies correctly and the dependency audit no longer reports the vulnerable cross-spawn version.
Written by the indexing model from the issue text.
Description
Regular Expression Denial of Service (ReDoS) in cross-spawn
I am getting this audit result using the latest tfx-cli package (0.18.0)
cross-spawn <6.0.6
Severity: high
Regular Expression Denial of Service (ReDoS) in cross-spawn - https://github.com/advisories/GHSA-3xgq-45jj-v275
fix available via npm audit fix --force
Will install [email protected], which is a breaking change
node_modules/cross-spawn
execa 0.5.0 - 0.9.0
Depends on vulnerable versions of cross-spawn
node_modules/execa
clipboardy <=1.2.3
Depends on vulnerable versions of execa
node_modules/clipboardy
tfx-cli >=0.6.0
Depends on vulnerable versions of clipboardy
node_modules/tfx-cli
Fixing this appears to be pretty simple. Upgrading clipboardy to 4.0.0 would resolve the issue. It looks like the api has changed slightly, but since it is only used on one line in tfcommand.ts it should be quite simple to upgrade.
- Dominant language
- TypeScript
- Stars
- 385
- Forks
- 142
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 5
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- No Dockerfile or Docker Compose file
- No pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from microsoft/tfs-cli
-
Area: tfx-cli triage
Difficulty 1/5 Under an hour Newbie friendliness 92/100
-
Area: tfx-cli triage
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
Area: tfx-cli DevOps enhancement
Difficulty 1/5 Under an hour Newbie friendliness 68/100
-
Area: tfx-cli triage
Difficulty 3/5 1-2 days Newbie friendliness 58/100
-
Area: tfx-cli triage
Difficulty 4/5 3-5 days Newbie friendliness 48/100
All issues in microsoft/tfs-cli
Similar issues
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
tomjn/coilbox-hub#454 ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Maintainers usually reply within 1 day
-
api: spanner
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
googleapis/google-cloud-node#9513 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 92/100
Maintainers usually reply within 1 day
-
SegmentedControl calls Math.random() during render, breaking Next.js cacheComponents prerenderingOpen
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
mantinedev/mantine#9244 ·
Maintainers usually reply within 8 days